CVE-2008-2266: Medium severity nzbget vulnerability
uulib/uunconc.c in UUDeview 0.5.20, as used in nzbget before 0.3.0 and possibly other products, allows local users to overwrite arbitrary files via a symlink attack on a temporary filename generated by the tempnam function. NOTE: this may be a CVE-2004-2265 regression.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2008-2266?
CVE-2008-2266 has a medium severity rating due to its potential impact on local file integrity.
How do I fix CVE-2008-2266?
To fix CVE-2008-2266, upgrade to a version of NZBGet later than 0.3.0 or ensure UUDeview is updated to a secure version.
What types of systems are affected by CVE-2008-2266?
CVE-2008-2266 affects local users of NZBGet versions up to 0.2.2 and UUDeview version 0.5.20.
What is the nature of the vulnerability in CVE-2008-2266?
CVE-2008-2266 is a symlink attack vulnerability that allows local users to overwrite arbitrary files.
Can CVE-2008-2266 be exploited remotely?
No, CVE-2008-2266 can only be exploited by local users with access to the affected systems.