The (1) fence_apc and (2) fence_apc_snmp programs, as used in (a) fence 2.02.00-r1 and possibly (b) cman, when running in verbose mode, allows local users to append to arbitrary files via a symlink attack on the apclog temporary file.
History

No history.

cve-icon MITRE

Status: PUBLISHED

Assigner: redhat

Published: 2008-10-15T20:00:00

Updated: 2024-08-07T10:24:19.341Z

Reserved: 2008-10-15T00:00:00

Link: CVE-2008-4579

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Modified

Published: 2008-10-15T20:08:02.730

Modified: 2023-02-13T02:19:32.213

Link: CVE-2008-4579

cve-icon Redhat

Severity : Low

Publid Date: 2008-10-08T00:00:00Z

Links: CVE-2008-4579 - Bugzilla