CVE-2008-6552
published 2009-03-30CVE-2008-6552: Red Hat Cluster Project 2.x allows local users to modify or overwrite arbitrary files via symlink attacks on files in /tmp, involving unspecified components in…
PriorityP422medium6.9CVSS 2.0
AVLACMAuNCCICAC
EPSS
0.39%
31.3th percentile
Red Hat Cluster Project 2.x allows local users to modify or overwrite arbitrary files via symlink attacks on files in /tmp, involving unspecified components in Resource Group Manager (aka rgmanager) before 2.03.09-1, gfs2-utils before 2.03.09-1, and CMAN - The Cluster Manager before 2.03.09-1 on Fedora 9.
Affected
43 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| fedoraproject | fedora | — | — |
| redhat | cluster_project | — | — |
| redhat | cluster_project | — | — |
| redhat | cluster_project | — | — |
| redhat | cluster_project | — | — |
| redhat | cluster_project | — | — |
| redhat | cluster_project | — | — |
| redhat | cluster_project | — | — |
| redhat | cluster_project | — | — |
| redhat | cluster_project | — | — |
| redhat | cluster_project | — | — |
| redhat | cluster_project | — | — |
| redhat | cluster_project | — | — |
| redhat | cluster_project | — | — |
| redhat | cluster_project | — | — |
| redhat | cluster_project | — | — |
| redhat | cluster_project | — | — |
| redhat | cluster_project | — | — |
| redhat | cluster_project | — | — |
| redhat | cluster_project | — | — |
| redhat | cluster_project | — | — |
| redhat | cluster_project | — | — |
| redhat | cluster_project | — | — |
| redhat | cluster_project | — | — |
| redhat | cluster_project | — | — |
CVSS provenance
nvdv2.06.9MEDIUMAV:L/AC:M/Au:N/C:C/I:C/A:C
vendor_redhat6.9MEDIUM
vendor_ubuntu6.9MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
Red Hat Cluster Suite vulnerabilities
vendor_ubuntu·2009-12-18·CVSS 6.9
CVE-2008-4192 [MEDIUM] Red Hat Cluster Suite vulnerabilities
Title: Red Hat Cluster Suite vulnerabilities
Summary: Red Hat Cluster Suite vulnerabilities
Multiple insecure temporary file handling vulnerabilities were discovered
in Red Hat Cluster. A local attacker could exploit these to overwrite
arbitrary local files via symlinks. (CVE-2008-4192, CVE-2008-4579,
CVE-2008-4580, CVE-2008-6552)
It was discovered that CMAN did not properly handle malformed configuration
files. An attacker could cause a denial of service (via CPU consumption and
memory corruption) in a node if the attacker were able to modify the
cluster configuration for the node. (CVE-2008-6560)
Instructions: In general, a standard system upgrade is sufficient to effect the
necessary changes.
Red Hat
rgmanager: multiple insecure temporary file use issues
vendor_redhat·2008-10-31·CVSS 6.9
CVE-2008-6552 [MEDIUM] CWE-377 rgmanager: multiple insecure temporary file use issues
rgmanager: multiple insecure temporary file use issues
Red Hat Cluster Project 2.x allows local users to modify or overwrite arbitrary files via symlink attacks on files in /tmp, involving unspecified components in Resource Group Manager (aka rgmanager) before 2.03.09-1, gfs2-utils before 2.03.09-1, and CMAN - The Cluster Manager before 2.03.09-1 on Fedora 9.
GHSA
GHSA-mmp4-x7mg-mw3w: Red Hat Cluster Project 2
ghsa_unreviewed·2022-05-17
CVE-2008-6552 [MEDIUM] CWE-59 GHSA-mmp4-x7mg-mw3w: Red Hat Cluster Project 2
Red Hat Cluster Project 2.x allows local users to modify or overwrite arbitrary files via symlink attacks on files in /tmp, involving unspecified components in Resource Group Manager (aka rgmanager) before 2.03.09-1, gfs2-utils before 2.03.09-1, and CMAN - The Cluster Manager before 2.03.09-1 on Fedora 9.
No detection rules found.
No public exploits indexed.
http://osvdb.org/50299http://osvdb.org/50300http://osvdb.org/50301http://rhn.redhat.com/errata/RHSA-2009-1337.htmlhttp://secunia.com/advisories/32602http://secunia.com/advisories/32616http://secunia.com/advisories/36530http://secunia.com/advisories/36555http://secunia.com/advisories/43367http://secunia.com/advisories/43372http://www.redhat.com/archives/fedora-package-announce/2008-November/msg00163.htmlhttp://www.redhat.com/archives/fedora-package-announce/2008-November/msg00164.htmlhttp://www.redhat.com/archives/fedora-package-announce/2008-November/msg00165.htmlhttp://www.redhat.com/support/errata/RHSA-2009-1339.htmlhttp://www.redhat.com/support/errata/RHSA-2009-1341.htmlhttp://www.redhat.com/support/errata/RHSA-2011-0264.htmlhttp://www.redhat.com/support/errata/RHSA-2011-0265.htmlhttp://www.securityfocus.com/bid/32179http://www.ubuntu.com/usn/USN-875-1http://www.vupen.com/english/advisories/2011/0416http://www.vupen.com/english/advisories/2011/0417https://exchange.xforce.ibmcloud.com/vulnerabilities/46412https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A11404http://osvdb.org/50299http://osvdb.org/50300http://osvdb.org/50301http://rhn.redhat.com/errata/RHSA-2009-1337.htmlhttp://secunia.com/advisories/32602http://secunia.com/advisories/32616http://secunia.com/advisories/36530http://secunia.com/advisories/36555http://secunia.com/advisories/43367http://secunia.com/advisories/43372http://www.redhat.com/archives/fedora-package-announce/2008-November/msg00163.htmlhttp://www.redhat.com/archives/fedora-package-announce/2008-November/msg00164.htmlhttp://www.redhat.com/archives/fedora-package-announce/2008-November/msg00165.htmlhttp://www.redhat.com/support/errata/RHSA-2009-1339.htmlhttp://www.redhat.com/support/errata/RHSA-2009-1341.htmlhttp://www.redhat.com/support/errata/RHSA-2011-0264.htmlhttp://www.redhat.com/support/errata/RHSA-2011-0265.htmlhttp://www.securityfocus.com/bid/32179http://www.ubuntu.com/usn/USN-875-1http://www.vupen.com/english/advisories/2011/0416http://www.vupen.com/english/advisories/2011/0417https://exchange.xforce.ibmcloud.com/vulnerabilities/46412https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A11404
2009-03-30
Published