PT-2008-6175 · Lazarus · Lazarus
Christian Hoffmann
+1
·
Published
2008-11-10
·
Updated
2017-08-08
·
CVE-2008-5007
CVSS v2.0
6.9
Medium
| Vector | AV:L/AC:M/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
Lazarus version 0.9.24
Description
The issue allows local users to overwrite or delete arbitrary files via a symlink attack on a (1) /tmp/lazarus.tgz temporary file or a (2) /tmp/lazarus temporary directory.
Recommendations
For Lazarus version 0.9.24, as a temporary workaround, consider restricting access to the create lazarus export tgz.sh script until a patch is available. Avoid using the script to prevent potential symlink attacks on temporary files or directories.
Exploit
Fix
Link Following
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Lazarus