rc.sysinit in initscripts before 8.76.3-1 on Fedora 9 and other Linux platforms allows local users to delete arbitrary files via a symlink attack on a file or directory under (1) /var/lock or (2) /var/run.
References
Configurations
Configuration 1 (hide)
AND |
|
History
21 Nov 2024, 00:49
Type | Values Removed | Values Added |
---|---|---|
References | () http://secunia.com/advisories/32037 - Vendor Advisory | |
References | () http://secunia.com/advisories/32710 - | |
References | () http://wiki.rpath.com/wiki/Advisories:rPSA-2008-0318 - | |
References | () http://www.securityfocus.com/bid/31385 - | |
References | () https://bugzilla.redhat.com/show_bug.cgi?id=458504 - | |
References | () https://bugzilla.redhat.com/show_bug.cgi?id=458652 - | |
References | () https://exchange.xforce.ibmcloud.com/vulnerabilities/45402 - | |
References | () https://issues.rpath.com/browse/RPL-2857 - | |
References | () https://www.redhat.com/archives/fedora-package-announce/2008-September/msg01135.html - |
Information
Published : 2008-09-29 17:17
Updated : 2024-11-21 00:49
NVD link : CVE-2008-3524
Mitre link : CVE-2008-3524
CVE.ORG link : CVE-2008-3524
JSON object : View
Products Affected
redhat
- initscripts
- fedora
CWE
CWE-59
Improper Link Resolution Before File Access ('Link Following')