Secunia Logo  


Secunia PSI WorldMap
 
CVE Reference: CVE-2008-1570
NOTE: The text on this page is written by CVE MITRE and reflects neither the opinions of Secunia or the results of our research. All data on this page is written and maintained by CVE MITRE.

Original Page at CVE MITRE:
CVE-2008-1570

Description:
Race condition in the create_lockpath function in policyd-weight 0.1.14 beta-16 allows local users to modify or delete arbitrary files by creating the LOCKPATH directory, then modifying it after the symbolic link check occurs. NOTE: this is due to an incomplete fix for CVE-2008-1569.

CVE Status:
Candidate

References:

XF
  http://xforce.iss.net/xforce/xfdb/41570

SAID
  Secunia Advisory: SA29738

OSVDB
  43888

GENTOO
  http://security.gentoo.org/glsa/glsa-200804-11.xml

CONFIRM


Return to the previous page.