CVE-2008-4936
Summary
| CVE | CVE-2008-4936 |
|---|---|
| State | PUBLISHED |
| Assigner | mitre |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2008-11-05 15:00:14 UTC |
| Updated | 2026-04-23 00:35:47 UTC |
| Description | faxspool in mgetty 1.1.36 allows local users to overwrite arbitrary files via a symlink attack on a /tmp/faxsp.##### temporary file. |
Risk And Classification
CVSS v2.0 Breakdown
Access Vector
LocalAccess Complexity
MediumAuthentication
NoneConfidentiality
CompleteIntegrity
CompleteAvailability
CompleteAV:L/AC:M/Au:N/C:C/I:C/A:C
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Gert Doering | Mgetty | 1.1.36 | All | All | All |
Vendor Declared Affected Products
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Mgetty 'faxspool' Insecure Temporary File Creation Vulnerability | af854a3a-2127-422b-91ae-364da2661108 | www.securityfocus.com | |
| Security Advisory SA33051 - Gentoo update for mgetty - Secunia | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | |
| Mgetty: Insecure temporary file usage — Gentoo Linux Documentation | af854a3a-2127-422b-91ae-364da2661108 | security.gentoo.org | |
| #496403 - The possibility of attack with the help of symlinks in some Debian packages - Debian Bug report logs | af854a3a-2127-422b-91ae-364da2661108 | bugs.debian.org | |
| IBM X-Force Exchange | af854a3a-2127-422b-91ae-364da2661108 | exchange.xforce.ibmcloud.com | |
| uvw.ru/report.lenny.txt | af854a3a-2127-422b-91ae-364da2661108 | uvw.ru | |
| oss-security - CVE requests: tempfile issues for aview, mgetty, openoffice, crossfire | af854a3a-2127-422b-91ae-364da2661108 | www.openwall.com | |
| 235770 – (debian-tempfile) [Tracker] Tempfile issues found in Debian | af854a3a-2127-422b-91ae-364da2661108 | bugs.gentoo.org | |
| Gentoo Bug 235806 - net-dialup/mgetty < 1.1.36-r3 insecure temp file usage (CVE-2008-4936) | af854a3a-2127-422b-91ae-364da2661108 | bugs.gentoo.org | |
| 404 Not Found | af854a3a-2127-422b-91ae-364da2661108 | dev.gentoo.org | Exploit |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
Vendor Comments And Credit
| Organization | Published | Contributor | Statement |
|---|---|---|---|
| Mandriva | 2008-12-09 | Vincent Danen | This issue was fixed on May 5, 2003 for all Mandriva Linux products. |
| Red Hat | 2008-11-06 | Tomas Hoger | Not vulnerable. This issue did not affect the versions of mgetty as shipped with Red Hat Enterprise Linux 2.1, 3, 4, or 5, as they include patch that resolves this issue. |
There are currently no legacy QID mappings associated with this CVE.