CVE-2008-0167
N/A
N/A
Summary
The write_array_file function in utils/include.pl in GForge 4.5.14 updates configuration files by truncating them to zero length and then writing new data, which might allow attackers to bypass intended access restrictions or have unspecified other impact in opportunistic circumstances.
Affected Software
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| n/a | n/a | n/a | affected |
Weaknesses
- n/a
ADP Enrichment
CVE Program Container
Additional References
- http://www.securityfocus.com/bid/29215
- http://secunia.com/advisories/30286
- http://security.debian.org/pool/updates/main/g/gforge/gforge_4.5.14-22etch8.diff.gz
- http://www.vupen.com/english/advisories/2008/1537/references
- http://secunia.com/advisories/30088
- http://www.debian.org/security/2008/dsa-1577
- https://exchange.xforce.ibmcloud.com/vulnerabilities/42456
References
- http://www.securityfocus.com/bid/29215
- http://secunia.com/advisories/30286
- http://security.debian.org/pool/updates/main/g/gforge/gforge_4.5.14-22etch8.diff.gz
- http://www.vupen.com/english/advisories/2008/1537/references
- http://secunia.com/advisories/30088
- http://www.debian.org/security/2008/dsa-1577
- https://exchange.xforce.ibmcloud.com/vulnerabilities/42456
Feedback
Was this page helpful?
Glad to hear it! Please tell us how we can improve.
Sorry to hear that. Please tell us how we can improve.