CVE-2008-3931: Medium severity realflex realwin vulnerability
Published Sep 4, 2008
·Updated
javareconf in R 2.7.2 allows local users to overwrite arbitrary files via a symlink attack on temporary files.
Affected Software
1 affected component
R Foundation R=2.7.2
Event History
Sep 4, 2008
CVE Published
via MITRE·06:00 PM
Data Sourced
via MITRE·06:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2008-3931?
CVE-2008-3931 has a moderate severity rating due to the potential for local users to exploit a symlink attack.
2
How do I fix CVE-2008-3931?
To fix CVE-2008-3931, ensure you do not allow untrusted users to create symlinks in the temporary file directories used by javareconf.
3
Which software versions are affected by CVE-2008-3931?
CVE-2008-3931 specifically affects R version 2.7.2.
4
What kind of attack is involved in CVE-2008-3931?
CVE-2008-3931 involves a symlink attack that allows local users to overwrite arbitrary files.
5
What is javareconf related to CVE-2008-3931?
Javareconf is a tool in R that is affected by CVE-2008-3931 due to its handling of temporary files.