CVE-2008-5145: Medium severity debian ltp vulnerability
Published Nov 18, 2008
·Updated
ltpmenu in ltp 20060918 allows local users to overwrite arbitrary files via a symlink attack on a /tmp/runltp.mainmenu.##### temporary file.
Affected Software
1 affected component
Debian Ltp=20060918
Event History
Nov 18, 2008
CVE Published
via MITRE·03:00 PM
Data Sourced
via MITRE·03:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2008-5145?
CVE-2008-5145 has a medium severity rating due to its potential for local users to exploit file permissions.
2
How do I fix CVE-2008-5145?
To fix CVE-2008-5145, you should update to a version of ltp that does not use temporary files in an insecure manner.
3
What type of attack does CVE-2008-5145 facilitate?
CVE-2008-5145 facilitates a symlink attack that can allow local users to overwrite arbitrary files.
4
Which software is affected by CVE-2008-5145?
CVE-2008-5145 specifically affects the ltp version 20060918 on Debian systems.
5
Is CVE-2008-5145 exploitable remotely?
No, CVE-2008-5145 is not remotely exploitable; it requires local access to the system.