First published: Thu Sep 04 2008(Updated: )
migrate_aliases.sh in Citadel Server 7.37 allows local users to overwrite arbitrary files via a symlink attack on a temporary file.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Citadel | =7.37-3 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2008-3930 is classified as a medium severity vulnerability due to the potential for arbitrary file overwrite.
To fix CVE-2008-3930, users should update Citadel Server to a patched version that mitigates the symlink attack.
Local users running Citadel Server version 7.37 are affected by CVE-2008-3930.
CVE-2008-3930 is a local privilege escalation vulnerability caused by a symlink attack on temporary files.
No, CVE-2008-3930 requires local access to exploit the symlink vulnerability.