Secunia Logo  


Secunia PSI WorldMap
 
CVE Reference: CVE-2008-4986
NOTE: The text on this page is written by CVE MITRE and reflects neither the opinions of Secunia or the results of our research. All data on this page is written and maintained by CVE MITRE.

Original Page at CVE MITRE:
CVE-2008-4986

Description:
wims 3.62 allows local users to overwrite arbitrary files via a symlink attack on (a) /tmp/env#####, (b) /tmp/sed#####, and (c) /tmp/referer-home.log temporary files, related to the (1) coqweb and (2) account.sh scripts.

CVE Status:
Candidate

References:

MLIST
  http://www.openwall.com/lists/oss-security/2008/10/30/2

CONFIRM
  http://dev.gentoo.org/~rbu/security/debiantemp/wims
  http://bugs.debian.org/496387

BID
  32244


Return to the previous page.