PT-2008-6175 · Lazarus · Lazarus

Christian Hoffmann

+1

·

Published

2008-11-10

·

Updated

2017-08-08

·

CVE-2008-5007

CVSS v2.0

6.9

Medium

VectorAV:L/AC:M/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Lazarus version 0.9.24
Description The issue allows local users to overwrite or delete arbitrary files via a symlink attack on a (1) /tmp/lazarus.tgz temporary file or a (2) /tmp/lazarus temporary directory.
Recommendations For Lazarus version 0.9.24, as a temporary workaround, consider restricting access to the create lazarus export tgz.sh script until a patch is available. Avoid using the script to prevent potential symlink attacks on temporary files or directories.

Exploit

Fix

Link Following

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2008-5007

Affected Products

Lazarus