CVE-2008-5135: Medium severity Debian Os-prober vulnerability
DISPUTED os-prober in os-prober 1.17 allows local users to overwrite arbitrary files via a symlink attack on the (1) /tmp/mounted-map or (2) /tmp/raided-map temporary file. NOTE: the vendor disputes this issue, stating "the insecure code path should only ever run inside a d-i environment, which has no non-root users."
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2008-5135?
The severity of CVE-2008-5135 is considered low as it involves a local file overwrite vulnerability.
How do I fix CVE-2008-5135?
To fix CVE-2008-5135, ensure the os-prober 1.17 is updated to a version that addresses the symlink attack.
Who is affected by CVE-2008-5135?
CVE-2008-5135 affects local users of os-prober 1.17 in Debian systems.
What type of vulnerability is CVE-2008-5135?
CVE-2008-5135 is a local file overwrite vulnerability due to a symlink attack.
Is CVE-2008-5135 still a threat?
CVE-2008-5135 is not currently considered a major threat due to its low severity and the specific environment it affects.