CVE-2008-4579: Low severity gentoo cman vulnerability
Common Vulnerabilities and Exposures assigned an identifier CVE-2008-4579 to the following vulnerability:
The (1) fenceapc and (2) fenceapcsnmp programs, as used in (a) fence 2.02.00-r1 and possibly (b) cman, when running in verbose mode, allows local users to append to arbitrary files via a symlink attack on the apclog temporary file.
References: http://bugs.gentoo.org/showbug.cgi?id=240576 http://www.openwall.com/lists/oss-security/2008/10/13/3
Affected Software
Event History
Parent advisories
This vulnerability appears in the following advisories.
Frequently Asked Questions
What is the severity of CVE-2008-4579?
CVE-2008-4579 is considered a moderate severity vulnerability due to its potential for local privilege escalation via a symlink attack.
How do I fix CVE-2008-4579?
To fix CVE-2008-4579, update the affected programs to newer versions, specifically fence 0:1.32.68-5.el4 or cman 0:2.0.115-1.el5 as recommended by the vendor.
Which software versions are affected by CVE-2008-4579?
CVE-2008-4579 affects Gentoo Fence 2.02.00-r1 and potentially cman 2.02.00-r1.
Is CVE-2008-4579 exploitable remotely?
CVE-2008-4579 is primarily a local vulnerability and requires local user access to exploit.
What does CVE-2008-4579 allow an attacker to do?
CVE-2008-4579 allows local users to append data to arbitrary files through a symlink attack on a temporary log file.