CVE-2008-6552: Medium severity redhat Cluster Project vulnerability
Red Hat Cluster Project 2.x allows local users to modify or overwrite arbitrary files via symlink attacks on files in /tmp, involving unspecified components in Resource Group Manager (aka rgmanager) before 2.03.09-1, gfs2-utils before 2.03.09-1, and CMAN - The Cluster Manager before 2.03.09-1 on Fedora 9.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2008-6552?
CVE-2008-6552 has a medium severity rating as it allows local users to overwrite arbitrary files via symlink attacks.
How do I fix CVE-2008-6552?
To fix CVE-2008-6552, upgrade to versions 2.03.09-1 or later of the affected Red Hat Cluster Project components.
Which software is affected by CVE-2008-6552?
CVE-2008-6552 affects Red Hat Cluster Project versions before 2.03.09-1, including rgmanager, gfs2-utils, and CMAN.
What type of attack does CVE-2008-6552 involve?
CVE-2008-6552 involves symlink attacks that exploit vulnerabilities in the Resource Group Manager.
Can I still use Red Hat Cluster Project if I have CVE-2008-6552?
While you can continue using Red Hat Cluster Project, you should implement the fix to mitigate the risk posed by CVE-2008-6552.