CVE-2008-4192
Publication date 29 September 2008
Last updated 24 July 2024
Ubuntu priority
The pserver_shutdown function in fence_egenera in cman 2.20080629 and 2.20080801 allows local users to overwrite arbitrary files via a symlink attack on the /tmp/eglog temporary file.
Status
Package | Ubuntu Release | Status |
---|---|---|
redhat-cluster | 9.10 karmic |
Not affected
|
9.04 jaunty |
Not affected
|
|
8.10 intrepid |
Fixed 2.20080826-0ubuntu1.3
|
|
8.04 LTS hardy |
Not affected
|
|
7.10 gutsy | Not in release | |
7.04 feisty | Not in release | |
6.06 LTS dapper | Not in release | |
redhat-cluster-suite | 9.10 karmic | Not in release |
9.04 jaunty | Not in release | |
8.10 intrepid | Not in release | |
8.04 LTS hardy | Not in release | |
7.10 gutsy |
Not affected
|
|
7.04 feisty |
Not affected
|
|
6.06 LTS dapper |
Not affected
|
Notes
jdstrand
up priority to low, as it may be possible to DoS the system (eg overwriting /etc/shadow with garbage data)