CVE-2008-4998: Medium severity Twiki TWiki vulnerability
Published Nov 7, 2008
·Updated
DISPUTED postinst in twiki 4.1.2 allows local users to overwrite arbitrary files via a symlink attack on the /tmp/twiki temporary file. NOTE: the vendor disputes this vulnerability, stating "this bug is invalid."
Affected Software
1 affected component
Twiki TWiki=4.1.2
Event History
Nov 7, 2008
CVE Published
via MITRE·07:00 PM
Data Sourced
via MITRE·07:00 PM
Description
Disputed
07:36 PM
Frequently Asked Questions
1
What is the severity of CVE-2008-4998?
CVE-2008-4998 is classified as a local privilege escalation vulnerability.
2
How do I fix CVE-2008-4998?
To mitigate CVE-2008-4998, users should avoid using the affected version 4.1.2 of Twiki and upgrade to a later version if available.
3
Who is affected by CVE-2008-4998?
CVE-2008-4998 primarily affects local users on systems running Twiki version 4.1.2.
4
What is the nature of the exploit in CVE-2008-4998?
The exploit in CVE-2008-4998 involves a symlink attack that allows local users to overwrite arbitrary files.
5
Has the vulnerability reported in CVE-2008-4998 been acknowledged?
The vendor disputes the existence of the vulnerability reported in CVE-2008-4998, stating it is invalid.