CVE-2008-6552

Red Hat Cluster Project 2.x allows local users to modify or overwrite arbitrary files via symlink attacks on files in /tmp, involving unspecified components in Resource Group Manager (aka rgmanager) before 2.03.09-1, gfs2-utils before 2.03.09-1, and CMAN - The Cluster Manager before 2.03.09-1 on Fedora 9.
Advertisement

NeevaHost hosting service

Configurations

Configuration 1 (hide)

OR cpe:2.3:a:redhat:cluster_project:2.01.00:*:*:*:*:*:*:*
cpe:2.3:a:redhat:cluster_project:2.02.00:*:*:*:*:*:*:*
cpe:2.3:a:redhat:cluster_project:2.03.08:*:*:*:*:*:*:*
cpe:2.3:a:redhat:cluster_project:2.03.09:*:*:*:*:*:*:*
cpe:2.3:a:redhat:cluster_project:2.99.04:*:*:*:*:*:*:*
cpe:2.3:a:redhat:cluster_project:2.99.05:*:*:*:*:*:*:*
cpe:2.3:a:redhat:cluster_project:2.99.06:*:*:*:*:*:*:*
cpe:2.3:a:redhat:cluster_project:2.99.13:*:*:*:*:*:*:*
cpe:2.3:a:redhat:cluster_project:2.03.03:*:*:*:*:*:*:*
cpe:2.3:a:redhat:cluster_project:2.03.04:*:*:*:*:*:*:*
cpe:2.3:a:redhat:cluster_project:2.99.00:*:*:*:*:*:*:*
cpe:2.3:a:redhat:cluster_project:2.03.01:*:*:*:*:*:*:*
cpe:2.3:a:redhat:cluster_project:2.99.09:*:*:*:*:*:*:*
cpe:2.3:a:redhat:cluster_project:2.99.10:*:*:*:*:*:*:*
cpe:2.3:a:redhat:cluster_project:2.99.02:*:*:*:*:*:*:*
cpe:2.3:a:redhat:cluster_project:2.03.11:*:*:*:*:*:*:*
cpe:2.3:a:redhat:cluster_project:2.99.08:*:*:*:*:*:*:*
cpe:2.3:a:redhat:cluster_project:2.03.7:*:*:*:*:*:*:*
cpe:2.3:a:redhat:cluster_project:2.99.12:*:*:*:*:*:*:*
cpe:2.3:a:redhat:cluster_project:2.03.05:*:*:*:*:*:*:*
cpe:2.3:a:redhat:cluster_project:2.03.10:*:*:*:*:*:*:*
cpe:2.3:a:redhat:cluster_project:2.99.03:*:*:*:*:*:*:*
cpe:2.3:a:redhat:cluster_project:2.99.01:*:*:*:*:*:*:*
cpe:2.3:a:redhat:cluster_project:2.00.00:*:*:*:*:*:*:*
cpe:2.3:a:redhat:cluster_project:2.03.00:*:*:*:*:*:*:*
cpe:2.3:a:redhat:cluster_project:2.99.11:*:*:*:*:*:*:*
cpe:2.3:a:redhat:cluster_project:2.99.07:*:*:*:*:*:*:*

Configuration 2 (hide)

AND
OR cpe:2.3:a:redhat:cman:2.03.08-1:*:*:*:*:*:*:*
cpe:2.3:a:redhat:rgmanager:2.03.03-1:*:*:*:*:*:*:*
cpe:2.3:a:redhat:cman:2.03.04-1:*:*:*:*:*:*:*
cpe:2.3:a:redhat:cman:2.03.03-1:*:*:*:*:*:*:*
cpe:2.3:a:redhat:rgmanager:2.03.07-1:*:*:*:*:*:*:*
cpe:2.3:a:redhat:rgmanager:2.03.08-1:*:*:*:*:*:*:*
cpe:2.3:a:redhat:cman:2.03.07-1:*:*:*:*:*:*:*
cpe:2.3:a:redhat:cman:2.03.05-1:*:*:*:*:*:*:*
cpe:2.3:o:fedoraproject:fedora:9:*:*:*:*:*:*:*
cpe:2.3:a:redhat:rgmanager:2.03.04-1:*:*:*:*:*:*:*
cpe:2.3:a:redhat:rgmanager:2.03.05-1:*:*:*:*:*:*:*
OR cpe:2.3:a:redhat:gfs2-utils:2.03.04-1:*:*:*:*:*:*:*
cpe:2.3:a:redhat:gfs2-utils:2.03.05-1:*:*:*:*:*:*:*
cpe:2.3:a:redhat:gfs2-utils:2.03.07-1:*:*:*:*:*:*:*
cpe:2.3:a:redhat:gfs2-utils:2.03.03-1:*:*:*:*:*:*:*
cpe:2.3:a:redhat:gfs2-utils:22.03.08-1:*:*:*:*:*:*:*

Information

Published : 2009-03-30 09:30

Updated : 2017-09-28 18:33


NVD link : CVE-2008-6552

Mitre link : CVE-2008-6552


JSON object : View

CWE
CWE-59

Improper Link Resolution Before File Access ('Link Following')

Advertisement

dedicated server usa

Products Affected

redhat

  • rgmanager
  • cman
  • cluster_project
  • gfs2-utils

fedoraproject

  • fedora