CVE-2008-5377: Medium severity cups vulnerability
Published Dec 8, 2008
·Updated
pstopdf in CUPS 1.3.8 allows local users to overwrite arbitrary files via a symlink attack on the /tmp/pstopdf.log temporary file, a different vulnerability than CVE-2001-1333.
Affected Software
1 affected component
apple CUPS=1.3.8
Event History
Dec 8, 2008
CVE Published
via MITRE·11:00 PM
Data Sourced
via MITRE·11:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2008-5377?
CVE-2008-5377 is considered a moderate severity vulnerability due to the potential for local users to exploit it.
2
How do I fix CVE-2008-5377?
To fix CVE-2008-5377, upgrade CUPS to a version later than 1.3.8 which has patched the vulnerability.
3
Who is affected by CVE-2008-5377?
CVE-2008-5377 affects users of CUPS version 1.3.8, particularly on systems where local users have access.
4
What type of attack is used in CVE-2008-5377?
CVE-2008-5377 utilizes a symlink attack to overwrite arbitrary files.
5
What is the impact of exploiting CVE-2008-5377?
Exploiting CVE-2008-5377 can lead to unauthorized file modifications on the affected system.