CVE-2008-2958

Race condition in (1) checkinstall 1.6.1 and (2) installwatch allows local users to overwrite arbitrary files and have other impacts via symlink and possibly other attacks on temporary working directories.
Configurations

Configuration 1 (hide)

cpe:2.3:a:checkinstall:checkinstall:1.6.1:*:*:*:*:*:*:*

History

21 Nov 2024, 00:48

Type Values Removed Values Added
References () http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=488140 - () http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=488140 -
References () http://lists.alioth.debian.org/pipermail/secure-testing-team/2008-June/001672.html - Exploit () http://lists.alioth.debian.org/pipermail/secure-testing-team/2008-June/001672.html - Exploit
References () http://secunia.com/advisories/30873 - Vendor Advisory () http://secunia.com/advisories/30873 - Vendor Advisory
References () https://exchange.xforce.ibmcloud.com/vulnerabilities/43440 - () https://exchange.xforce.ibmcloud.com/vulnerabilities/43440 -

Information

Published : 2008-07-01 22:41

Updated : 2024-11-21 00:48


NVD link : CVE-2008-2958

Mitre link : CVE-2008-2958

CVE.ORG link : CVE-2008-2958


JSON object : View

Products Affected

checkinstall

  • checkinstall
CWE
CWE-362

Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')