CVE-2008-6552: Medium severity redhat Cluster Project vulnerability

Published Mar 30, 2009
·
Updated

Red Hat Cluster Project 2.x allows local users to modify or overwrite arbitrary files via symlink attacks on files in /tmp, involving unspecified components in Resource Group Manager (aka rgmanager) before 2.03.09-1, gfs2-utils before 2.03.09-1, and CMAN - The Cluster Manager before 2.03.09-1 on Fedora 9.

Affected Software

59 affected components
redhat Cluster Project=2.03.01
redhat Cluster Project=2.03.04
redhat Cluster Project=2.99.09
redhat Cluster Project=2.99.10
redhat Cluster Project=2.99.02
redhat Cluster Project=2.03.11
redhat Cluster Project=2.99.08
redhat Cluster Project=2.03.7
redhat Cluster Project=2.99.06
redhat Cluster Project=2.99.12
redhat Cluster Project=2.01.00
redhat Cluster Project=2.99.05
redhat Cluster Project=2.03.05
redhat Cluster Project=2.99.00
redhat Cluster Project=2.03.10
redhat Cluster Project=2.03.03
redhat Cluster Project=2.99.13
redhat Cluster Project=2.99.03
redhat Cluster Project=2.03.09
redhat Cluster Project=2.99.01
redhat Cluster Project=2.03.08
redhat Cluster Project=2.00.00
redhat Cluster Project=2.03.00
redhat Cluster Project=2.02.00
redhat Cluster Project=2.99.11
redhat Cluster Project=2.99.04
redhat Cluster Project=2.99.07
redhat Cman=2.03.03-1
redhat Cman=2.03.04-1
redhat Cman=2.03.05-1
redhat Cman=2.03.07-1
redhat Cman=2.03.08-1
redhat Rgmanager=2.03.03-1
redhat Rgmanager=2.03.04-1
redhat Rgmanager=2.03.05-1
redhat Rgmanager=2.03.07-1
redhat Rgmanager=2.03.08-1
Fedoraproject Fedora=9
redhat Gfs2-utils=2.03.03-1
redhat Gfs2-utils=2.03.04-1
redhat Gfs2-utils=2.03.05-1
redhat Gfs2-utils=2.03.07-1
redhat Gfs2-utils=22.03.08-1
All of the following
Any of the following
redhat Cman=2.03.03-1
redhat Cman=2.03.04-1
redhat Cman=2.03.05-1
redhat Cman=2.03.07-1
redhat Cman=2.03.08-1
redhat Rgmanager=2.03.03-1
redhat Rgmanager=2.03.04-1
redhat Rgmanager=2.03.05-1
redhat Rgmanager=2.03.07-1
redhat Rgmanager=2.03.08-1
Fedoraproject Fedora=9
Any of the following
redhat Gfs2-utils=2.03.03-1
redhat Gfs2-utils=2.03.04-1
redhat Gfs2-utils=2.03.05-1
redhat Gfs2-utils=2.03.07-1
redhat Gfs2-utils=22.03.08-1

Event History

Mar 30, 2009
CVE Published
via MITRE·04:00 PM
Data Sourced
via MITRE·04:00 PM
Description
Data Sourced
via NVD·04:30 PM
DescriptionSeverityWeaknessAffected Software

Frequently Asked Questions

1

What is the severity of CVE-2008-6552?

CVE-2008-6552 has a medium severity rating as it allows local users to overwrite arbitrary files via symlink attacks.

2

How do I fix CVE-2008-6552?

To fix CVE-2008-6552, upgrade to versions 2.03.09-1 or later of the affected Red Hat Cluster Project components.

3

Which software is affected by CVE-2008-6552?

CVE-2008-6552 affects Red Hat Cluster Project versions before 2.03.09-1, including rgmanager, gfs2-utils, and CMAN.

4

What type of attack does CVE-2008-6552 involve?

CVE-2008-6552 involves symlink attacks that exploit vulnerabilities in the Resource Group Manager.

5

Can I still use Red Hat Cluster Project if I have CVE-2008-6552?

While you can continue using Red Hat Cluster Project, you should implement the fix to mitigate the risk posed by CVE-2008-6552.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203