CVE-2008-4192
published 2008-09-29CVE-2008-4192: The pserver_shutdown function in fence_egenera in cman 2.20080629 and 2.20080801 allows local users to overwrite arbitrary files via a symlink attack on the…
PriorityP423medium6.9CVSS 2.0
AVLACMAuNCCICAC
EXPLOIT
EPSS
0.71%
49.4th percentile
The pserver_shutdown function in fence_egenera in cman 2.20080629 and 2.20080801 allows local users to overwrite arbitrary files via a symlink attack on the /tmp/eglog temporary file.
Affected
2 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| redhat | cman | — | — |
| redhat | cman | — | — |
CVSS provenance
nvdv2.06.9MEDIUMAV:L/AC:M/Au:N/C:C/I:C/A:C
vendor_redhat6.9MEDIUM
vendor_ubuntu6.9MEDIUM
CVEs like this are exactly what “Exploited This Week” covers.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-hpx5-6mfx-fq22: The pserver_shutdown function in fence_egenera in cman 2
ghsa_unreviewed·2022-05-02
CVE-2008-4192 [MEDIUM] CWE-59 GHSA-hpx5-6mfx-fq22: The pserver_shutdown function in fence_egenera in cman 2
The pserver_shutdown function in fence_egenera in cman 2.20080629 and 2.20080801 allows local users to overwrite arbitrary files via a symlink attack on the /tmp/eglog temporary file.
Ubuntu
Red Hat Cluster Suite vulnerabilities
vendor_ubuntu·2009-12-18·CVSS 6.9
CVE-2008-4192 [MEDIUM] Red Hat Cluster Suite vulnerabilities
Title: Red Hat Cluster Suite vulnerabilities
Summary: Red Hat Cluster Suite vulnerabilities
Multiple insecure temporary file handling vulnerabilities were discovered
in Red Hat Cluster. A local attacker could exploit these to overwrite
arbitrary local files via symlinks. (CVE-2008-4192, CVE-2008-4579,
CVE-2008-4580, CVE-2008-6552)
It was discovered that CMAN did not properly handle malformed configuration
files. An attacker could cause a denial of service (via CPU consumption and
memory corruption) in a node if the attacker were able to modify the
cluster configuration for the node. (CVE-2008-6560)
Instructions: In general, a standard system upgrade is sufficient to effect the
necessary changes.
Red Hat
cman/fence: insecure temporary file usage in the egenera fence agent
vendor_redhat·2008-08-24·CVSS 6.9
CVE-2008-4192 [MEDIUM] CWE-377 cman/fence: insecure temporary file usage in the egenera fence agent
cman/fence: insecure temporary file usage in the egenera fence agent
The pserver_shutdown function in fence_egenera in cman 2.20080629 and 2.20080801 allows local users to overwrite arbitrary files via a symlink attack on the /tmp/eglog temporary file.
No detection rules found.
http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=496410http://dev.gentoo.org/~rbu/security/debiantemp/cmanhttp://secunia.com/advisories/31887http://secunia.com/advisories/32387http://secunia.com/advisories/32390http://secunia.com/advisories/43362http://uvw.ru/report.lenny.txthttp://www.openwall.com/lists/oss-security/2008/09/18/3http://www.openwall.com/lists/oss-security/2008/09/24/2http://www.openwall.com/lists/oss-security/2008/10/30/2http://www.redhat.com/support/errata/RHSA-2011-0266.htmlhttp://www.securityfocus.com/bid/30898http://www.ubuntu.com/usn/USN-875-1http://www.vupen.com/english/advisories/2011/0419https://bugs.gentoo.org/show_bug.cgi?id=235770https://bugzilla.redhat.com/show_bug.cgi?id=460476https://exchange.xforce.ibmcloud.com/vulnerabilities/44845https://www.redhat.com/archives/fedora-package-announce/2008-October/msg00666.htmlhttp://bugs.debian.org/cgi-bin/bugreport.cgi?bug=496410http://dev.gentoo.org/~rbu/security/debiantemp/cmanhttp://secunia.com/advisories/31887http://secunia.com/advisories/32387http://secunia.com/advisories/32390http://secunia.com/advisories/43362http://uvw.ru/report.lenny.txthttp://www.openwall.com/lists/oss-security/2008/09/18/3http://www.openwall.com/lists/oss-security/2008/09/24/2http://www.openwall.com/lists/oss-security/2008/10/30/2http://www.redhat.com/support/errata/RHSA-2011-0266.htmlhttp://www.securityfocus.com/bid/30898http://www.ubuntu.com/usn/USN-875-1http://www.vupen.com/english/advisories/2011/0419https://bugs.gentoo.org/show_bug.cgi?id=235770https://bugzilla.redhat.com/show_bug.cgi?id=460476https://exchange.xforce.ibmcloud.com/vulnerabilities/44845https://www.redhat.com/archives/fedora-package-announce/2008-October/msg00666.html
2008-09-29
Published