CVE-2007-4998
published 2008-01-31CVE-2007-4998: cp, when running with an option to preserve symlinks on multiple OSes, allows local, user-assisted attackers to overwrite arbitrary files via a symlink attack…
PriorityP420medium6.9CVSS 2.0
AVLACMAuNCCICAC
EPSS
0.35%
27.0th percentile
cp, when running with an option to preserve symlinks on multiple OSes, allows local, user-assisted attackers to overwrite arbitrary files via a symlink attack using crafted directories containing multiple source files that are copied to the same destination.
Affected
7 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | coreutils | < coreutils 4.1.2 (bookworm) | coreutils 4.1.2 (bookworm) |
| gnu | coreutils | >= 0 < 4.1.2 | 4.1.2 |
| gnu | coreutils | >= 0 < 4.1.2 | 4.1.2 |
| gnu | coreutils | >= 0 < 4.1.2 | 4.1.2 |
| gnu | coreutils | >= 0 < 4.1.2 | 4.1.2 |
| msrc | cbl_mariner_1.0_arm | — | — |
| msrc | cbl_mariner_1.0_x64 | — | — |
CVSS provenance
nvdv2.06.9MEDIUMAV:L/AC:M/Au:N/C:C/I:C/A:C
osv6.9MEDIUM
vendor_debian6.9MEDIUM
vendor_msrc6.9MEDIUM
vendor_redhat6.9MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Microsoft
CVE-2007-4998: NIST NVD Details: https://nvd
vendor_msrc·2020-09-08·CVSS 6.9
CVE-2007-4998 [MEDIUM] CVE-2007-4998: NIST NVD Details: https://nvd
NIST NVD Details: https://nvd.nist.gov/vuln/detail/CVE-2007-4998
Managed by Mariner: Managed by Mariner
[email protected]: [email protected]
Exploit Status: DOS:N/A
Remediation: kernel
Red Hat
cp symlink overwrite
vendor_redhat·2008-01-22·CVSS 6.9
CVE-2007-4998 [MEDIUM] cp symlink overwrite
cp symlink overwrite
cp, when running with an option to preserve symlinks on multiple OSes, allows local, user-assisted attackers to overwrite arbitrary files via a symlink attack using crafted directories containing multiple source files that are copied to the same destination.
Statement: This issue affects the busybox package in Red Hat Enterprise Linux 2.1, 3, 4, and 5,
This issue affects the fileutils package in Red Hat Enterprise Linux 2.1.
This issue affects the coreutils package in Red Hat Enterprise Linux 3.
The coreutils package in Red Hat Enterprise Linux 4 and 5 are not vulnerable to this issue.
Given this issue has minimal risk we do not intend to issues updates to correct this issue in affected versions of Red Hat Enterprise Linux.
For more information please see:
https://bu
Debian
CVE-2007-4998: coreutils - cp, when running with an option to preserve symlinks on multiple OSes, allows lo...
vendor_debian·2007·CVSS 6.9
CVE-2007-4998 [MEDIUM] CVE-2007-4998: coreutils - cp, when running with an option to preserve symlinks on multiple OSes, allows lo...
cp, when running with an option to preserve symlinks on multiple OSes, allows local, user-assisted attackers to overwrite arbitrary files via a symlink attack using crafted directories containing multiple source files that are copied to the same destination.
Scope: local
bookworm: resolved (fixed in 4.1.2)
bullseye: resolved (fixed in 4.1.2)
forky: resolved (fixed in 4.1.2)
sid: resolved (fixed in 4.1.2)
trixie: resolved (fixed in 4.1.2)
GHSA
GHSA-4337-x4h9-rx8j: cp, when running with an option to preserve symlinks on multiple OSes, allows local, user-assisted attackers to overwrite arbitrary files via a symlin
ghsa_unreviewed·2022-05-01
CVE-2007-4998 [MEDIUM] CWE-59 GHSA-4337-x4h9-rx8j: cp, when running with an option to preserve symlinks on multiple OSes, allows local, user-assisted attackers to overwrite arbitrary files via a symlin
cp, when running with an option to preserve symlinks on multiple OSes, allows local, user-assisted attackers to overwrite arbitrary files via a symlink attack using crafted directories containing multiple source files that are copied to the same destination.
OSV
CVE-2007-4998: cp, when running with an option to preserve symlinks on multiple OSes, allows local, user-assisted attackers to overwrite arbitrary files via a symlin
osv·2008-01-31·CVSS 6.9
CVE-2007-4998 [MEDIUM] CVE-2007-4998: cp, when running with an option to preserve symlinks on multiple OSes, allows local, user-assisted attackers to overwrite arbitrary files via a symlin
cp, when running with an option to preserve symlinks on multiple OSes, allows local, user-assisted attackers to overwrite arbitrary files via a symlink attack using crafted directories containing multiple source files that are copied to the same destination.
No detection rules found.
No public exploits indexed.
2008-01-31
Published