PT-2008-1155 · Patchlink+1 · Patchlink Update+1
Larry W. Cashdollar
+1
·
Published
2008-01-31
·
Updated
2018-12-11
·
CVE-2008-0525
CVSS v2.0
4.6
Medium
| Vector | AV:L/AC:L/Au:N/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
PatchLink Update client for Unix versions 6.2094 through 6.4102
Description
The issue allows local users to truncate arbitrary files via a symlink attack on the /tmp/patchlink.tmp file used by the logtrimmer script, and execute arbitrary code via a symlink attack on the /tmp/plshutdown file used by the rebootTask script. This can potentially lead to unauthorized access to confidential data, disruption of data integrity, and denial of service.
Recommendations
For versions 6.2094 through 6.4102, consider restricting access to the logtrimmer script and the rebootTask script to minimize the risk of exploitation. As a temporary workaround, avoid using the /tmp/patchlink.tmp and /tmp/plshutdown files until a patch is available. At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Link Following
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Alt Linux
Patchlink Update