Bugsalert.com
Security News about Viruses, Spyware,
Trojans, Malware, XSS attacks.

CVE-2008-4108 (python)

BugsAlert Home > CVE-2008-4108 (python)
 
 

Tools/faqwiz/move-faqwiz.sh (aka the generic FAQ wizard moving tool) in Python 2.4.5 might allow local users to overwrite arbitrary files via a symlink attack on a tmp$RANDOM.tmp temporary file. NOTE: there may not be common usage scenarios in which tmp$RANDOM.tmp is located in an untrusted directory.




Original Source: http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2008-4108

Learn more about CVE-2008-4108 (python)
 
Tags: cve-2008-4108 python

Related Items

      TROJ_IFRAME.CP

      Recycling Ancient Phishing Tricks

      BuzzyWall "search" SQL Injection Vulnerability

      FrSIRT - Slackware Security Update Fixes Ruby Code Execution Vulnerabilities

      Ubuntu Security Update Fixes OpenSSH Cookie Handling Security Issue

      Bugtraq: [ GLSA 200802-06 ] scponly: Multiple vulnerabilities

      CVE-2007-6033 (InTouch)

 

Pixel