CVE-2008-5374: Medium severity bash-doc vulnerability
Published Dec 8, 2008
·Updated
bash-doc 3.2 allows local users to overwrite arbitrary files via a symlink attack on a /tmp/cb#####.? temporary file, related to the (1) aliasconv.sh, (2) aliasconv.bash, and (3) cshtobash scripts.
Affected Software
1 affected component
Matthias Klose Bash-doc=3.2
Event History
Dec 8, 2008
CVE Published
via MITRE·11:00 PM
Data Sourced
via MITRE·11:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2008-5374?
CVE-2008-5374 is classified as a medium severity vulnerability due to its potential to allow local users to overwrite arbitrary files.
2
How do I fix CVE-2008-5374?
To fix CVE-2008-5374, ensure that the affected bash-doc version 3.2 is updated to a version that addresses the symlink vulnerability.
3
What systems are affected by CVE-2008-5374?
CVE-2008-5374 affects bash-doc version 3.2 on systems that utilize this software package.
4
What type of vulnerability is CVE-2008-5374?
CVE-2008-5374 is a symlink vulnerability that allows local attacks to create and manipulate temporary files.
5
Can CVE-2008-5374 be exploited remotely?
No, CVE-2008-5374 requires local access to the system to exploit the vulnerability.