CVE-2008-5142: Medium severity freebsd send-pr vulnerability
Published Nov 18, 2008
·Updated
sendbug in freebsd-sendpr 3.113+5.3 on Debian GNU/Linux allows local users to overwrite arbitrary files via a symlink attack on a /tmp/pr.##### temporary file.
Affected Software
1 affected component
FreeBSD freebsd-sendpr=3.113\+5.3
Event History
Nov 18, 2008
CVE Published
via MITRE·03:00 PM
Data Sourced
via MITRE·03:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2008-5142?
CVE-2008-5142 is classified as a local privilege escalation vulnerability that allows users to overwrite arbitrary files.
2
How do I fix CVE-2008-5142?
To fix CVE-2008-5142, users should update to a patched version of freebsd-sendpr that mitigates the symlink attack.
3
Who is affected by CVE-2008-5142?
CVE-2008-5142 affects local users on systems running freebsd-sendpr version 3.113+5.3 on Debian GNU/Linux.
4
What type of attack does CVE-2008-5142 involve?
CVE-2008-5142 involves a symlink attack that exploits the temporary file handling in freebsd-sendpr.
5
What is the impact of CVE-2008-5142?
The impact of CVE-2008-5142 includes the potential for local users to overwrite sensitive files, leading to data loss or compromise.