Vulnerability Description
Red Hat Cluster Project 2.x allows local users to modify or overwrite arbitrary files via symlink attacks on files in /tmp, involving unspecified components in Resource Group Manager (aka rgmanager) before 2.03.09-1, gfs2-utils before 2.03.09-1, and CMAN - The Cluster Manager before 2.03.09-1 on Fedora 9.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Redhat | Cluster Project | 2.00.00 |
| Redhat | Cman | 2.03.03-1 |
| Redhat | Rgmanager | 2.03.03-1 |
| Fedoraproject | Fedora | 9 |
| Redhat | Gfs2-Utils | 2.03.03-1 |
Related Weaknesses (CWE)
References
- http://osvdb.org/50299
- http://osvdb.org/50300
- http://osvdb.org/50301
- http://rhn.redhat.com/errata/RHSA-2009-1337.html
- http://secunia.com/advisories/32602Vendor Advisory
- http://secunia.com/advisories/32616
- http://secunia.com/advisories/36530
- http://secunia.com/advisories/36555
- http://secunia.com/advisories/43367
- http://secunia.com/advisories/43372
- http://www.redhat.com/archives/fedora-package-announce/2008-November/msg00163.htVendor Advisory
- http://www.redhat.com/archives/fedora-package-announce/2008-November/msg00164.htVendor Advisory
- http://www.redhat.com/archives/fedora-package-announce/2008-November/msg00165.htVendor Advisory
- http://www.redhat.com/support/errata/RHSA-2009-1339.html
- http://www.redhat.com/support/errata/RHSA-2009-1341.html
FAQ
What is CVE-2008-6552?
CVE-2008-6552 is a vulnerability with a CVSS score of 6.9 (MEDIUM). Red Hat Cluster Project 2.x allows local users to modify or overwrite arbitrary files via symlink attacks on files in /tmp, involving unspecified components in Resource Group Manager (aka rgmanager) b...
How severe is CVE-2008-6552?
CVE-2008-6552 has been rated MEDIUM with a CVSS base score of 6.9/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2008-6552?
Check the references section above for vendor advisories and patch information. Affected products include: Redhat Cluster Project, Redhat Cman, Redhat Rgmanager, Fedoraproject Fedora, Redhat Gfs2-Utils.