MEDIUM · 6.9

CVE-2008-1570

Race condition in the create_lockpath function in policyd-weight 0.1.14 beta-16 allows local users to modify or delete arbitrary files by creating the LOCKPATH directory, then modifying it after the s...

Vulnerability Description

Race condition in the create_lockpath function in policyd-weight 0.1.14 beta-16 allows local users to modify or delete arbitrary files by creating the LOCKPATH directory, then modifying it after the symbolic link check occurs. NOTE: this is due to an incomplete fix for CVE-2008-1569.

CVSS Score

6.9

MEDIUM

AV:L/AC:M/Au:N/C:C/I:C/A:C
Confidentiality
COMPLETE
Integrity
COMPLETE
Availability
COMPLETE

Affected Products

VendorProductVersions
Policyd-WeightPolicyd-Weight0.1.14_beta-14

Related Weaknesses (CWE)

References

FAQ

What is CVE-2008-1570?

CVE-2008-1570 is a vulnerability with a CVSS score of 6.9 (MEDIUM). Race condition in the create_lockpath function in policyd-weight 0.1.14 beta-16 allows local users to modify or delete arbitrary files by creating the LOCKPATH directory, then modifying it after the s...

How severe is CVE-2008-1570?

CVE-2008-1570 has been rated MEDIUM with a CVSS base score of 6.9/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2008-1570?

Check the references section above for vendor advisories and patch information. Affected products include: Policyd-Weight Policyd-Weight.