oss-sec mailing list archives

Re: CVE id request: mon


From: "Steven M. Christey" <coley () linus mitre org>
Date: Tue, 7 Oct 2008 17:05:13 -0400 (EDT)


======================================================
Name: CVE-2008-4477
Status: Candidate
URL: http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-4477
Reference: MLIST:[debian-devel] 20080812 Re: Possible mass bug filing: The possibility of attack with the help of 
symlinks in some Debian packages
Reference: URL:http://lists.debian.org/debian-devel/2008/08/msg00312.html
Reference: CONFIRM:http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=496398

alert.d/test.alert in mon 0.99.2 allows local users to overwrite
arbitrary files via a symlink attack on the test.alert.log temporary
file.



Current thread: