CVE-2008-4950: Medium severity debian debconf i18n vulnerability
DISPUTED gccross in dpkg-cross 2.3.0 allows local users to overwrite arbitrary files via a symlink attack on the tmp/gccross2.log temporary file. NOTE: the vendor disputes this vulnerability, stating that "There is no sense in this bug - the script ... is called under specific cross-building environments within a chroot."
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2008-4950?
The severity of CVE-2008-4950 is disputed, but it potentially allows local user manipulation of temporary files.
How do I fix CVE-2008-4950?
To fix CVE-2008-4950, it's recommended to avoid using dpkg-cross 2.3.0 or to implement proper file permissioning to prevent symlink attacks.
Who is affected by CVE-2008-4950?
Users running dpkg-cross version 2.3.0 on Debian systems may be affected by CVE-2008-4950.
What type of attack is described in CVE-2008-4950?
CVE-2008-4950 describes a symlink attack that local users can exploit to overwrite arbitrary files.
What software version does CVE-2008-4950 pertain to?
CVE-2008-4950 pertains specifically to dpkg-cross version 2.3.0.