PT-2008-5258 · Honeyd · Honeyd
Published
2008-09-04
·
Updated
2017-08-08
·
CVE-2008-3928
CVSS v2.0
6.9
Medium
| Vector | AV:L/AC:M/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
Honeyd version 1.5c
Description
The issue allows local users to potentially overwrite arbitrary files via a symlink attack on a temporary file created by the test.sh script in Honeyd.
Recommendations
For Honeyd version 1.5c, consider restricting access to the test.sh script until a patch is available, or apply configuration changes to prevent temporary files from being created in insecure locations.
Fix
Link Following
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Honeyd