First published: Tue Nov 18 2008(Updated: )
ltpmenu in ltp 20060918 allows local users to overwrite arbitrary files via a symlink attack on a /tmp/runltp.mainmenu.##### temporary file.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Debian Ltp | =20060918 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2008-5145 has a medium severity rating due to its potential for local users to exploit file permissions.
To fix CVE-2008-5145, you should update to a version of ltp that does not use temporary files in an insecure manner.
CVE-2008-5145 facilitates a symlink attack that can allow local users to overwrite arbitrary files.
CVE-2008-5145 specifically affects the ltp version 20060918 on Debian systems.
No, CVE-2008-5145 is not remotely exploitable; it requires local access to the system.