Vulnerability Description
wyrd 1.4.3b allows local users to overwrite arbitrary files via a symlink attack on the wyrd-tmp.[USERID] temporary file.
CVSS Score
3.6
LOW
AV:L/AC:L/Au:N/C:P/I:P/A:N
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Paul Pelzl | Wyrd | 1.4.3b_3 |
Related Weaknesses (CWE)
References
- http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=466382Exploit
- http://secunia.com/advisories/29009Vendor Advisory
- http://secunia.com/advisories/29113
- http://www.securityfocus.com/bid/27848
- https://bugzilla.redhat.com/show_bug.cgi?id=433719
- https://www.redhat.com/archives/fedora-package-announce/2008-February/msg00825.h
- https://www.redhat.com/archives/fedora-package-announce/2008-February/msg00841.h
- http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=466382Exploit
- http://secunia.com/advisories/29009Vendor Advisory
- http://secunia.com/advisories/29113
- http://www.securityfocus.com/bid/27848
- https://bugzilla.redhat.com/show_bug.cgi?id=433719
- https://www.redhat.com/archives/fedora-package-announce/2008-February/msg00825.h
- https://www.redhat.com/archives/fedora-package-announce/2008-February/msg00841.h
FAQ
What is CVE-2008-0806?
CVE-2008-0806 is a vulnerability with a CVSS score of 3.6 (LOW). wyrd 1.4.3b allows local users to overwrite arbitrary files via a symlink attack on the wyrd-tmp.[USERID] temporary file.
How severe is CVE-2008-0806?
CVE-2008-0806 has been rated LOW with a CVSS base score of 3.6/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2008-0806?
Check the references section above for vendor advisories and patch information. Affected products include: Paul Pelzl Wyrd.