PT-2008-1124 · Gentoo Linux · Am-Utils

·

CVE-2008-1078

·

Published

2008-02-29

·

Updated

2023-02-13

CVSS v2.0

7.2

High

VectorAV:L/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions am-utils versions prior to 6.1.5
Description The issue affects the am-utils package in Gentoo Linux and potentially other distributions, allowing local users to exploit it and compromise the confidentiality, integrity, and availability of protected information. This can be achieved through a symlink attack on temporary files, specifically targeting the expn[PID] file, enabling local users to overwrite arbitrary files.
Recommendations For versions prior to 6.1.5, update to version 6.1.5 or later to resolve the issue. As a temporary workaround, consider restricting access to the expn function to minimize the risk of exploitation.

Exploit

Fix

Link Following

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2015-09628
CVE-2008-1078

Affected Products

Am-Utils