firehol in firehol 1.256 allows local users to overwrite arbitrary files via a symlink attack on (1) /tmp/.firehol-tmp-#####-*-* and (2) /tmp/firehol.conf temporary files. NOTE: the vendor disputes this vulnerability, stating that an attack "would require an attacker to create 1073741824*PID-RANGE symlinks.
Metrics
Affected Vendors & Products
References
History
No history.
MITRE
Status: PUBLISHED
Assigner: mitre
Published: 2008-11-05T14:51:00Z
Updated: 2024-09-17T02:53:26.055Z
Reserved: 2008-11-05T00:00:00Z
Link: CVE-2008-4953
Vulnrichment
No data.
NVD
Status : Modified
Published: 2008-11-05T15:00:15.273
Modified: 2024-11-21T00:52:55.767
Link: CVE-2008-4953
Redhat
No data.