Lucene search

K
cveMitreCVE-2008-5146
HistoryNov 18, 2008 - 4:00 p.m.

CVE-2008-5146

2008-11-1816:00:01
CWE-59
mitre
web.nvd.nist.gov
28
cve
2008
5146
local users
overwrite
arbitrary files
symlink attack
tmp
accession
nvd

CVSS2

6.9

Attack Vector

LOCAL

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:L/AC:M/Au:N/C:C/I:C/A:C

AI Score

6.3

Confidence

High

EPSS

0

Percentile

5.1%

add-accession-numbers in ctn 3.0.6 allows local users to overwrite arbitrary files via a symlink attack on the /tmp/accession temporary file.

Affected configurations

Nvd
Node
erl_wustlctnMatch3.0.6
VendorProductVersionCPE
erl_wustlctn3.0.6cpe:2.3:a:erl_wustl:ctn:3.0.6:*:*:*:*:*:*:*

CVSS2

6.9

Attack Vector

LOCAL

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:L/AC:M/Au:N/C:C/I:C/A:C

AI Score

6.3

Confidence

High

EPSS

0

Percentile

5.1%