CVE-2008-4440: High severity debian feta vulnerability
Published Oct 3, 2008
·Updated
The to-upgrade plugin in feta 1.4.16 allows local users to overwrite arbitrary files via a symlink on the (1) /tmp/feta.install.$USER and (2) /tmp/feta.avail.$USER temporary files.
Affected Software
1 affected component
Debian Feta
Event History
Oct 3, 2008
CVE Published
via MITRE·10:00 PM
Data Sourced
via MITRE·10:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2008-4440?
CVE-2008-4440 is classified as a moderate severity vulnerability.
2
How can I mitigate CVE-2008-4440?
To mitigate CVE-2008-4440, ensure that users do not have write access to the /tmp directory or use a secure file transfer method instead.
3
Who is affected by CVE-2008-4440?
CVE-2008-4440 affects local users of the feta plugin in Debian systems.
4
What types of attacks can be executed using CVE-2008-4440?
CVE-2008-4440 can allow local users to exploit the symlink vulnerability to overwrite arbitrary files.
5
Is there a patch available for CVE-2008-4440?
As of now, there is no specific patch mentioned for CVE-2008-4440, but updating or removing the vulnerable plugin is recommended.