Common Vulnerabilities and Exposures assigned an identifier CVE-2008-4579 to the following vulnerability:
The (1) fenceapc and (2) fenceapcsnmp programs, as used in (a) fence 2.02.00-r1 and possibly (b) cman, when running in verbose mode, allows local users to append to arbitrary files via a symlink attack on the apclog temporary file.
References: http://bugs.gentoo.org/showbug.cgi?id=240576 http://www.openwall.com/lists/oss-security/2008/10/13/3
fencemanual, as used in fence 2.02.00-r1 and possibly cman, allows local users to modify arbitrary files via a symlink attack on the fencemanual.fifo temporary file.