First published: Thu Nov 06 2008(Updated: )
linux-patch-openswan 2.4.12 allows local users to overwrite arbitrary files via a symlink attack on (a) /tmp/snap##### and (b) /tmp/nightly##### temporary files, related to the (1) maysnap and (2) maytest scripts.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Openswan | =2.4.12 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2008-4966 is considered a moderate severity vulnerability due to its potential for local users to exploit file permissions.
To remediate CVE-2008-4966, ensure you update to a version of Openswan that does not include this vulnerability.
CVE-2008-4966 affects users of the linux-patch-openswan version 2.4.12.
CVE-2008-4966 is associated with a symlink attack that can overwrite arbitrary files.
CVE-2008-4966 is a local vulnerability, meaning it requires local user access to exploit.