PT-2008-1031 · Debian · Hf+1

Steve Kemp

·

Published

2008-11-26

·

Updated

2017-08-08

·

CVE-2008-2378

CVSS v2.0

7.2

High

VectorAV:L/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions hf versions 0.7.3 through 0.8
Description The issue concerns multiple vulnerabilities in the hf package of the Debian GNU/Linux operating system, which can be exploited by a local attacker to compromise the confidentiality, integrity, and availability of protected information. A specific vulnerability exists in the hfkernel, where improper handling of the -k option allows local users to gain privileges via a Trojan horse killall program in a directory in the PATH.
Recommendations For versions 0.7.3 through 0.8, consider restricting access to the killall program to minimize the risk of exploitation until a patch is available. As a temporary workaround, avoid using the -k option in the hfkernel until the issue is resolved.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2015-02618
CVE-2008-2378
DSA-1668-1

Affected Products

Debian
Hf