CVE-2008-4580
Summary
| CVE | CVE-2008-4580 |
|---|---|
| State | PUBLISHED |
| Assigner | redhat |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2008-10-15 20:08:02 UTC |
| Updated | 2026-04-23 00:35:47 UTC |
| Description | fence_manual, as used in fence 2.02.00-r1 and possibly cman, allows local users to modify arbitrary files via a symlink attack on the fence_manual.fifo temporary file. |
Risk And Classification
Primary CVSS: v2.0 7.2 from [email protected]
AV:L/AC:L/Au:N/C:C/I:C/A:C
Problem Types: CWE-59 | NVD-CWE-noinfo | n/a
CVSS v2.0 Breakdown
Access Vector
LocalAccess Complexity
LowAuthentication
NoneConfidentiality
CompleteIntegrity
CompleteAvailability
CompleteAV:L/AC:L/Au:N/C:C/I:C/A:C
NVD Known Affected Configurations (CPE 2.3)
Vendor Declared Affected Products
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| oss-security - Re: CVE Request | af854a3a-2127-422b-91ae-364da2661108 | www.openwall.com | |
| Gentoo Bug 240576 - sys-cluster/fence-2.02.00-r1 symlink vulnerability (CVE-2008-{4579,4580}) | af854a3a-2127-422b-91ae-364da2661108 | bugs.gentoo.org | |
| oss-security - Re: CVE Request | af854a3a-2127-422b-91ae-364da2661108 | www.openwall.com | |
| IBM X-Force Exchange | af854a3a-2127-422b-91ae-364da2661108 | exchange.xforce.ibmcloud.com | |
| USN-875-1: Red Hat Cluster Suite vulnerabilities | Ubuntu | af854a3a-2127-422b-91ae-364da2661108 | www.ubuntu.com | |
| CVE-2008-4580 - Red Hat Customer Portal | MITRE | access.redhat.com | |
| 467387 – (CVE-2008-4580) CVE-2008-4580 cman/fence: insecure temporary file usage in the manual fence agent | MITRE | bugzilla.redhat.com | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
Vendor Comments And Credit
| Organization | Published | Contributor | Statement |
|---|---|---|---|
| Red Hat | 2009-11-12 | Tomas Hoger | Manual fencing agent is documented to only be provided for testing purposes and should not be used in production environments. Therefore, there is no plan to fix this flaw in Red Hat Cluster Suite for Red Hat Enterprise Linux 4, and in Red Hat Enterprise Linux 5. |
There are currently no legacy QID mappings associated with this CVE.