PT-2008-6300 · Smsclient · Smsclient

Published

2008-11-18

·

Updated

2009-02-17

·

CVE-2008-5155

CVSS v2.0

9.3

High

VectorAV:N/AC:M/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions smsclient version 2.0.8z
Description The issue allows local users to overwrite arbitrary files via a symlink attack on temporary files /tmp/header.##### or /tmp/body.#####, or append data to arbitrary files via a symlink attack on the /tmp/sms.log temporary file.
Recommendations For smsclient version 2.0.8z, consider restricting access to the temporary files /tmp/header.#####, /tmp/body.#####, and /tmp/sms.log to prevent symlink attacks until a patch is available. As a temporary workaround, avoid using the mail2sms.sh script in smsclient until the issue is resolved.

Exploit

Fix

Link Following

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2008-5155

Affected Products

Smsclient