| Vulnerability Name: | CVE-2008-4553 (CCN-44831) | ||||||||||||||||
| Assigned: | 2008-08-24 | ||||||||||||||||
| Published: | 2008-08-24 | ||||||||||||||||
| Updated: | 2017-08-08 | ||||||||||||||||
| Summary: | qemu-make-debian-root in qemu 0.9.1-5 on Debian GNU/Linux allows local users to overwrite arbitrary files via a symlink attack on temporary files and directories. | ||||||||||||||||
| CVSS v3 Severity: | 5.1 Medium (CCN CVSS v3.1 Vector: CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L)
| ||||||||||||||||
| CVSS v2 Severity: | 7.2 High (CVSS v2 Vector: AV:L/AC:L/Au:N/C:C/I:C/A:C) 6.2 Medium (Temporal CVSS v2 Vector: AV:L/AC:L/Au:N/C:C/I:C/A:C/E:H/RL:OF/RC:C)
2.9 Low (CCN Temporal CVSS v2 Vector: AV:L/AC:M/Au:N/C:N/I:P/A:P/E:H/RL:OF/RC:C)
| ||||||||||||||||
| Vulnerability Type: | CWE-59 | ||||||||||||||||
| Vulnerability Consequences: | File Manipulation | ||||||||||||||||
| References: | Source: CCN Type: QEMU Web page QEMU Source: CCN Type: Debian Bug report logs - #496394 The possibility of attack with the help of symlinks in some Debian packages Source: CONFIRM Type: UNKNOWN http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=496394 Source: MITRE Type: CNA CVE-2008-4553 Source: CONFIRM Type: Exploit http://dev.gentoo.org/~rbu/security/debiantemp/qemu Source: SECUNIA Type: UNKNOWN 32335 Source: CCN Type: Dmitry E. Oboukhov Advisory Package: qemu Source: MISC Type: UNKNOWN http://uvw.ru/report.lenny.txt Source: DEBIAN Type: UNKNOWN DSA-1657 Source: DEBIAN Type: DSA-1657 qemu -- insecure temporary files Source: MLIST Type: UNKNOWN [oss-security] 20081013 CVE id request: qemu Source: MLIST Type: UNKNOWN [oss-security] 20081014 Re: CVE id request: qemu Source: MLIST Type: Exploit [oss-security] 20081030 CVE requests: tempfile issues for aview, mgetty, openoffice, crossfire Source: CCN Type: OSVDB ID: 49165 QEMU qemu-make-debian-root Temporary File Symlink Arbitrary File Overwrite Source: BID Type: UNKNOWN 30931 Source: CCN Type: BID-30931 QEMU 'qemu-make-debian-root' Insecure Temporary File Creation Vulnerability Source: CONFIRM Type: UNKNOWN https://bugs.gentoo.org/show_bug.cgi?id=235770 Source: CONFIRM Type: UNKNOWN https://bugs.gentoo.org/show_bug.cgi?id=235826 Source: XF Type: UNKNOWN qemu-qemumakedebianroot-symlink(44831) Source: XF Type: UNKNOWN qemu-qemumakedebianroot-symlink(44831) | ||||||||||||||||
| Vulnerable Configuration: | Configuration 1: Denotes that component is vulnerable | ||||||||||||||||
| Oval Definitions | |||||||||||||||||
| |||||||||||||||||
| BACK | |||||||||||||||||