CVE-2008-0666

Publication date 11 February 2008

Last updated 24 July 2024


Ubuntu priority

Website META Language (WML) 2.0.11 allows local users to overwrite arbitrary files via a symlink attack on (1) the /tmp/pe.tmp.$$ temporary file used by wml_contrib/wmg.cgi and (2) temporary files used by wml_backend/p3_eperl/eperl_sys.c.

Status

No maintained releases are affected by this CVE.

Package Ubuntu Release Status
wml 7.10 gutsy
Fixed 2.0.11-2ubuntu0.1
7.04 feisty
Fixed 2.0.11-1ubuntu0.1
6.10 edgy
Fixed 2.0.8-11ubuntu0.6.10
6.06 LTS dapper
Fixed 2.0.8-11ubuntu0.6.06

Patch details

For informational purposes only. We recommend not to cherry-pick updates. How can I get the fixes?

Package Patch details
wml