CVE-2008-5135
N/A
N/A
Summary
os-prober in os-prober 1.17 allows local users to overwrite arbitrary files via a symlink attack on the (1) /tmp/mounted-map or (2) /tmp/raided-map temporary file. NOTE: the vendor disputes this issue, stating "the insecure code path should only ever run inside a d-i environment, which has no non-root users.
Affected Software
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| n/a | n/a | n/a | affected |
Weaknesses
- n/a
ADP Enrichment
CVE Program Container
Additional References
- http://lists.debian.org/debian-devel/2008/08/msg00296.html
- http://lists.debian.org/debian-devel/2008/08/msg00285.html
References
- http://lists.debian.org/debian-devel/2008/08/msg00296.html
- http://lists.debian.org/debian-devel/2008/08/msg00285.html
Feedback
Was this page helpful?
Glad to hear it! Please tell us how we can improve.
Sorry to hear that. Please tell us how we can improve.