First published: Thu Nov 06 2008(Updated: )
i2myspell in myspell 3.1 allows local users to overwrite arbitrary files via a symlink attack on (1) /tmp/i2my#####.1 and (2) /tmp/i2my#####.2 temporary files.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Debian Myspell | =3.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2008-4973 is rated as a medium severity vulnerability due to its potential to allow local users to exploit symlink attacks.
To fix CVE-2008-4973, update the myspell package to a version that includes the patch addressing symlink vulnerabilities.
CVE-2008-4973 affects local users of myspell version 3.1 running on Debian systems.
CVE-2008-4973 enables local users to overwrite arbitrary files through a symlink attack on temporary files.
The threat level of CVE-2008-4973 depends on the presence of an unpatched version of myspell 3.1 on systems in use.