CVE-2008-4639: Medium severity jhead vulnerability
Published Oct 21, 2008
·Updated
jhead.c in Matthias Wandel jhead 2.84 and earlier allows local users to overwrite arbitrary files via a symlink attack on a temporary file.
Affected Software
21 affected components
Sentex Jhead=2.6
Sentex Jhead<=2.84
Sentex Jhead=2.82
Sentex Jhead=1.5
Sentex Jhead=2.3
Sentex Jhead=2.5
Sentex Jhead=1.3
Sentex Jhead=2.4-2
Sentex Jhead=1.2
Sentex Jhead=1.8
Sentex Jhead=2.0
Sentex Jhead=2.7
Sentex Jhead=2.4-1
Sentex Jhead=1.6
Sentex Jhead=2.4
Sentex Jhead=1.9
Sentex Jhead=1.7
Sentex Jhead=1.4
Sentex Jhead=2.1
Sentex Jhead=2.8
Sentex Jhead=2.2
Event History
Oct 21, 2008
CVE Published
via MITRE·04:00 PM
Data Sourced
via MITRE·04:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2008-4639?
CVE-2008-4639 has been classified as a medium severity vulnerability.
2
How do I fix CVE-2008-4639?
To fix CVE-2008-4639, upgrade jhead to version 2.85 or later.
3
What type of attack does CVE-2008-4639 allow?
CVE-2008-4639 allows local users to perform a symlink attack to overwrite arbitrary files.
4
Which versions of jhead are affected by CVE-2008-4639?
CVE-2008-4639 affects jhead versions up to and including 2.84.
5
Can CVE-2008-4639 be exploited remotely?
CVE-2008-4639 can only be exploited locally, as it requires local user access to the affected system.