Lucene search

K
ubuntucveUbuntu.comUB:CVE-2008-4190
HistorySep 24, 2008 - 12:00 a.m.

CVE-2008-4190

2008-09-2400:00:00
ubuntu.com
ubuntu.com
10

CVSS2

4.4

Attack Vector

LOCAL

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:L/AC:M/Au:N/C:P/I:P/A:P

EPSS

0

Percentile

0.4%

The IPSEC livetest tool in Openswan 2.4.12 and earlier, and 2.6.x through
2.6.16, allows local users to overwrite arbitrary files and execute
arbitrary code via a symlink attack on the (1) ipseclive.conn and (2)
ipsec.olts.remote.log temporary files. NOTE: in many distributions and the
upstream version, this tool has been disabled.

CVSS2

4.4

Attack Vector

LOCAL

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:L/AC:M/Au:N/C:P/I:P/A:P

EPSS

0

Percentile

0.4%