CVE-2008-4966: Medium severity openswan vulnerability
Published Nov 6, 2008
·Updated
linux-patch-openswan 2.4.12 allows local users to overwrite arbitrary files via a symlink attack on (a) /tmp/snap##### and (b) /tmp/nightly##### temporary files, related to the (1) maysnap and (2) maytest scripts.
Affected Software
1 affected component
Openswan linux-patch-openswan=2.4.12
Event History
Nov 6, 2008
CVE Published
via MITRE·11:00 AM
Data Sourced
via MITRE·11:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2008-4966?
CVE-2008-4966 is considered a moderate severity vulnerability due to its potential for local users to exploit file permissions.
2
How do I fix CVE-2008-4966?
To remediate CVE-2008-4966, ensure you update to a version of Openswan that does not include this vulnerability.
3
Who is affected by CVE-2008-4966?
CVE-2008-4966 affects users of the linux-patch-openswan version 2.4.12.
4
What type of attack is associated with CVE-2008-4966?
CVE-2008-4966 is associated with a symlink attack that can overwrite arbitrary files.
5
Is CVE-2008-4966 a local or remote vulnerability?
CVE-2008-4966 is a local vulnerability, meaning it requires local user access to exploit.