| Vulnerability Name: | CVE-2008-4579 (CCN-45950) | ||||||||||||||||||||||||
| Assigned: | 2008-10-08 | ||||||||||||||||||||||||
| Published: | 2008-10-08 | ||||||||||||||||||||||||
| Updated: | 2023-02-13 | ||||||||||||||||||||||||
| Summary: | The (1) fence_apc and (2) fence_apc_snmp programs, as used in (a) fence 2.02.00-r1 and possibly (b) cman, when running in verbose mode, allows local users to append to arbitrary files via a symlink attack on the apclog temporary file. | ||||||||||||||||||||||||
| CVSS v3 Severity: | 5.1 Medium (CCN CVSS v3.1 Vector: CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L)
| ||||||||||||||||||||||||
| CVSS v2 Severity: | 1.9 Low (CVSS v2 Vector: AV:L/AC:M/Au:N/C:N/I:P/A:N) 1.5 Low (Temporal CVSS v2 Vector: AV:L/AC:M/Au:N/C:N/I:P/A:N/E:H/RL:OF/RC:UR)
2.7 Low (CCN Temporal CVSS v2 Vector: AV:L/AC:M/Au:N/C:N/I:P/A:P/E:H/RL:OF/RC:UR)
1.3 Low (REDHAT Temporal CVSS v2 Vector: AV:L/AC:M/Au:S/C:N/I:P/A:N/E:H/RL:OF/RC:UR)
| ||||||||||||||||||||||||
| Vulnerability Type: | CWE-377 | ||||||||||||||||||||||||
| Vulnerability Consequences: | File Manipulation | ||||||||||||||||||||||||
| References: | Source: CCN Type: Gentoo Bugzilla Bug 240576 sys-cluster/fence-2.02.00-r1 symlink vulnerability Source: secalert@redhat.com Type: UNKNOWN secalert@redhat.com Source: MITRE Type: CNA CVE-2008-4579 Source: CCN Type: cman Web page sys-cluster/cman Source: CCN Type: fence Web page sys-cluster/fence Source: CCN Type: RHSA-2009-1341 Low: cman security, bug fix, and enhancement update Source: CCN Type: RHSA-2011-0266 Low: fence security, bug fix, and enhancement update Source: CCN Type: SA41642 Gentoo fence Insecure Temporary Files Source: CCN Type: GLSA-201009-09 fence: Multiple symlink vulnerabilites Source: CCN Type: oss-security Mailing List, Mon, 13 Oct 2008 16:17:16 +0200 Re: CVE Request Source: secalert@redhat.com Type: UNKNOWN secalert@redhat.com Source: secalert@redhat.com Type: UNKNOWN secalert@redhat.com Source: secalert@redhat.com Type: UNKNOWN secalert@redhat.com Source: CCN Type: BID-31904 fence 'fence_apc' and 'fence_apc_snmp' Insecure Temporary File Creation Vulnerabilities Source: secalert@redhat.com Type: UNKNOWN secalert@redhat.com Source: CCN Type: USN-875-1 Red Hat Cluster Suite vulnerabilities Source: secalert@redhat.com Type: UNKNOWN secalert@redhat.com Source: secalert@redhat.com Type: UNKNOWN secalert@redhat.com Source: secalert@redhat.com Type: UNKNOWN secalert@redhat.com Source: XF Type: UNKNOWN fence-cman-apclog-symlink(45950) Source: secalert@redhat.com Type: UNKNOWN secalert@redhat.com Source: secalert@redhat.com Type: UNKNOWN secalert@redhat.com | ||||||||||||||||||||||||
| Vulnerable Configuration: | Configuration RedHat 1: Configuration CCN 1: Denotes that component is vulnerable | ||||||||||||||||||||||||
| Oval Definitions | |||||||||||||||||||||||||
| |||||||||||||||||||||||||
| BACK | |||||||||||||||||||||||||