CVE-2008-4474: High severity freeradius freeradius vulnerability
Published Oct 7, 2008
·Updated
freeradius-dialupadmin in freeradius 2.0.4 allows local users to overwrite arbitrary files via a symlink attack on temporary files in (1) backupradacct, (2) cleanradacct, (3) monthlytotstats, (4) totstats, and (5) truncateradacct.
Affected Software
1 affected component
FreeRADIUS freeradius=2.0.4
Event History
Oct 7, 2008
CVE Published
via MITRE·09:00 PM
Data Sourced
via MITRE·09:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2008-4474?
CVE-2008-4474 is considered a moderate severity vulnerability due to its potential for local users to perform symlink attacks.
2
How do I fix CVE-2008-4474?
To fix CVE-2008-4474, upgrade FreeRADIUS to a version later than 2.0.4 that addresses this symlink vulnerability.
3
What versions of FreeRADIUS are affected by CVE-2008-4474?
CVE-2008-4474 specifically affects FreeRADIUS version 2.0.4.
4
What types of attacks can CVE-2008-4474 facilitate?
CVE-2008-4474 can facilitate symlink attacks, allowing local users to overwrite arbitrary files.
5
Is there a patch available for CVE-2008-4474?
No official patch is listed for CVE-2008-4474; upgrading to a secure version is recommended.