CVE-2009-3304: Low severity gforge vulnerability
GForge 4.5.14, 4.7 rc2, and 4.8.2 allows local users to overwrite arbitrary files via a symlink attack on authorizedkeys files in users' home directories, related to deb-specific/sshdumpupdate.pl and cronjobs/cvs-cron/sshcreate.php.
Affected Software
Remediation
Patch Available
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2009-3304?
CVE-2009-3304 is considered a moderate severity vulnerability due to its potential for local exploitation through symlink attacks.
How do I fix CVE-2009-3304?
To fix CVE-2009-3304, ensure that authorized_keys files are protected from symlink attacks, and consider upgrading to a patched version of GForge.
Who is affected by CVE-2009-3304?
Users of GForge versions 4.5.14, 4.7 rc2, and 4.8.2 are affected by CVE-2009-3304.
What type of attack is described in CVE-2009-3304?
CVE-2009-3304 describes a symlink attack that allows local users to overwrite arbitrary files.
What components are related to CVE-2009-3304?
CVE-2009-3304 is related to deb-specific scripts like ssh_dump_update.pl and cronjobs for ssh_create.php.