Lucene search

K
cveMitreCVE-2008-5313
HistoryDec 03, 2008 - 5:30 p.m.

CVE-2008-5313

2008-12-0317:30:00
CWE-59
mitre
web.nvd.nist.gov
33
cve-2008-5313
mailscanner
symlink attack
file overwrite
nvd
security vulnerability

CVSS2

6.9

Attack Vector

LOCAL

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:L/AC:M/Au:N/C:C/I:C/A:C

AI Score

4.9

Confidence

High

EPSS

0

Percentile

5.1%

mailscanner 4.68.8 and other versions before 4.74.16-1 might allow local users to overwrite arbitrary files via a symlink attack on certain temporary files used by the (1) f-prot-autoupdate, (2) clamav-autoupdate, (3) avast-autoupdate, and (4) f-prot-6-autoupdate scripts in /etc/MailScanner/autoupdate/; the (5) bitdefender-wrapper, (6) kaspersky-wrapper, (7) clamav-wrapper, and (8) rav-wrapper scripts in /etc/MailScanner/wrapper/; the (9) Quarantine.pm, (10) TNEF.pm, (11) MessageBatch.pm, (12) WorkArea.pm, and (13) SA.pm scripts in /usr/share/MailScanner/MailScanner/; (14) /usr/sbin/MailScanner; and (15) scripts that load the /etc/MailScanner/mailscanner.conf.with.mcp configuration file.

Affected configurations

Nvd
Node
mailscannermailscannerMatch4.68.8
OR
mailscannermailscannerMatch4.68.8-1
OR
mailscannermailscannerMatch4.69.9-3
OR
mailscannermailscannerMatch4.70.7-1
OR
mailscannermailscannerMatch4.71.10-1
OR
mailscannermailscannerMatch4.72.5-1
OR
mailscannermailscannerMatch4.73.4-2
VendorProductVersionCPE
mailscannermailscanner4.68.8cpe:2.3:a:mailscanner:mailscanner:4.68.8:*:*:*:*:*:*:*
mailscannermailscanner4.68.8-1cpe:2.3:a:mailscanner:mailscanner:4.68.8-1:*:*:*:*:*:*:*
mailscannermailscanner4.69.9-3cpe:2.3:a:mailscanner:mailscanner:4.69.9-3:*:*:*:*:*:*:*
mailscannermailscanner4.70.7-1cpe:2.3:a:mailscanner:mailscanner:4.70.7-1:*:*:*:*:*:*:*
mailscannermailscanner4.71.10-1cpe:2.3:a:mailscanner:mailscanner:4.71.10-1:*:*:*:*:*:*:*
mailscannermailscanner4.72.5-1cpe:2.3:a:mailscanner:mailscanner:4.72.5-1:*:*:*:*:*:*:*
mailscannermailscanner4.73.4-2cpe:2.3:a:mailscanner:mailscanner:4.73.4-2:*:*:*:*:*:*:*

CVSS2

6.9

Attack Vector

LOCAL

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:L/AC:M/Au:N/C:C/I:C/A:C

AI Score

4.9

Confidence

High

EPSS

0

Percentile

5.1%