PT-2008-5411 · Python+1 · Python+2

Jan Lieskovsky

·

Published

2008-09-18

·

Updated

2017-08-08

·

CVE-2008-4108

CVSS v2.0

7.2

High

VectorAV:L/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions move-faqwiz.sh (aka the generic FAQ wizard moving tool) in Python 2.4.5
Description The issue allows local users to potentially overwrite arbitrary files via a symlink attack on a temporary file named tmp$RANDOM.tmp. It is noted that there may not be common usage scenarios where tmp$RANDOM.tmp is located in an untrusted directory.
Recommendations For move-faqwiz.sh in Python 2.4.5, consider restricting access to the tmp directory to prevent symlink attacks on the tmp$RANDOM.tmp temporary file until a more permanent solution is available.

Fix

Link Following

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2008-4108

Affected Products

Debian
Python
Move-Faqwiz.Sh