CVE-2008-3524
published 2008-09-29CVE-2008-3524: rc.sysinit in initscripts before 8.76.3-1 on Fedora 9 and other Linux platforms allows local users to delete arbitrary files via a symlink attack on a file or…
PriorityP414medium4.7CVSS 2.0
AVLACMAuNCNINAC
EPSS
0.35%
27.1th percentile
rc.sysinit in initscripts before 8.76.3-1 on Fedora 9 and other Linux platforms allows local users to delete arbitrary files via a symlink attack on a file or directory under (1) /var/lock or (2) /var/run.
Affected
4 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| redhat | fedora | — | — |
| redhat | initscripts | — | — |
| rpath | initscripts | — | — |
| rpath | initscripts | — | — |
CVSS provenance
nvdv2.04.7MEDIUMAV:L/AC:M/Au:N/C:N/I:N/A:C
vendor_redhat4.7MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-hh9c-wjp6-58h4: rc
ghsa_unreviewed·2022-05-17·CVSS 4.7
CVE-2008-4832 [MEDIUM] CWE-59 GHSA-hh9c-wjp6-58h4: rc
rc.sysinit in initscripts 8.12-8.21 and 8.56.15-0.1 on rPath allows local users to delete arbitrary files via a symlink attack on a directory under (1) /var/lock or (2) /var/run. NOTE: this issue exists because of a race condition in an incorrect fix for CVE-2008-3524. NOTE: exploitation may require an unusual scenario in which rc.sysinit is executed other than at boot time.
GHSA
GHSA-wf5r-cxjr-47w7: rc
ghsa_unreviewed·2022-05-02
CVE-2008-3524 [MEDIUM] CWE-59 GHSA-wf5r-cxjr-47w7: rc
rc.sysinit in initscripts before 8.76.3-1 on Fedora 9 and other Linux platforms allows local users to delete arbitrary files via a symlink attack on a file or directory under (1) /var/lock or (2) /var/run.
Red Hat
initscripts: possible system files removal via malicious symlink in /var/{lock,run}
vendor_redhat·2008-08-08·CVSS 4.7
CVE-2008-3524 [MEDIUM] initscripts: possible system files removal via malicious symlink in /var/{lock,run}
initscripts: possible system files removal via malicious symlink in /var/{lock,run}
rc.sysinit in initscripts before 8.76.3-1 on Fedora 9 and other Linux platforms allows local users to delete arbitrary files via a symlink attack on a file or directory under (1) /var/lock or (2) /var/run.
No detection rules found.
No public exploits indexed.
http://secunia.com/advisories/32037http://secunia.com/advisories/32710http://wiki.rpath.com/wiki/Advisories:rPSA-2008-0318http://www.securityfocus.com/bid/31385https://bugzilla.redhat.com/show_bug.cgi?id=458504https://bugzilla.redhat.com/show_bug.cgi?id=458652https://exchange.xforce.ibmcloud.com/vulnerabilities/45402https://issues.rpath.com/browse/RPL-2857https://www.redhat.com/archives/fedora-package-announce/2008-September/msg01135.htmlhttp://secunia.com/advisories/32037http://secunia.com/advisories/32710http://wiki.rpath.com/wiki/Advisories:rPSA-2008-0318http://www.securityfocus.com/bid/31385https://bugzilla.redhat.com/show_bug.cgi?id=458504https://bugzilla.redhat.com/show_bug.cgi?id=458652https://exchange.xforce.ibmcloud.com/vulnerabilities/45402https://issues.rpath.com/browse/RPL-2857https://www.redhat.com/archives/fedora-package-announce/2008-September/msg01135.html
2008-09-29
Published