CVE-2008-4108
Summary
| CVE | CVE-2008-4108 |
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2008-09-18 17:59:00 UTC |
| Updated | 2017-08-08 01:32:00 UTC |
| Description | Tools/faqwiz/move-faqwiz.sh (aka the generic FAQ wizard moving tool) in Python 2.4.5 might allow local users to overwrite arbitrary files via a symlink attack on a tmp$RANDOM.tmp temporary file. NOTE: there may not be common usage scenarios in which tmp$RANDOM.tmp is located in an untrusted directory. |
NVD Known Affected Configurations (CPE 2.3)
References
| Reference | Source | Link | Tags |
|---|
| Python 'move-faqwiz.sh' Insecure Temporary File Creation Vulnerability |
BID |
www.securityfocus.com |
|
| Python 'move-faqwiz.sh' Uses Unsafe Temporary Files That Let Local Users Gain Elevated Privileges - SecurityTracker |
SECTRACK |
www.securitytracker.com |
|
| '[oss-security] CVE Request (python)' - MARC |
MLIST |
marc.info |
|
| IBM X-Force Exchange |
XF |
exchange.xforce.ibmcloud.com |
|
| Webmail - OVH |
VUPEN |
www.vupen.com |
|
| 'Re: [oss-security] CVE Request (python)' - MARC |
MLIST |
marc.info |
|
| SecurityReason - python-2.3.4-5 Symbolic link attack possibility |
SREASON |
securityreason.com |
|
| #498899 - Unsecure use of temporary files - Debian Bug report logs |
CONFIRM |
bugs.debian.org |
|
| Bug 462326 – CVE-2008-4108 python: Generic FAQ wizard moving tool insecure auxiliary /tmp file usage (symlink attack possible) |
CONFIRM |
bugzilla.redhat.com |
|
| CVE Program record |
CVE.ORG |
www.cve.org |
canonical |
| NVD vulnerability detail |
NVD |
nvd.nist.gov |
canonical, analysis |
Vendor Comments And Credit
| Organization | Published | Contributor | Statement |
|---|
| Red Hat | 2009-03-13 | Tomas Hoger | Not vulnerable. This issue did not affect the versions of python as shipped with Red Hat Enterprise Linux 2.1, 3, 4, or 5. |
There are currently no legacy QID mappings associated with this CVE.