CVE-2017-8108
published 2017-06-08CVE-2017-8108: Unspecified tests in Lynis before 2.5.0 allow local users to write to arbitrary files or possibly gain privileges via a symlink attack on a temporary file.
PriorityP336high7.8CVSS 3.0
AVLACLPRLUINSUCHIHAH
EPSS
0.43%
35.1th percentile
Unspecified tests in Lynis before 2.5.0 allow local users to write to arbitrary files or possibly gain privileges via a symlink attack on a temporary file.
Affected
6 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| cisofy | lynis | < 2.5.0 | 2.5.0 |
| cisofy | lynis | >= 0 < 2.5.0-1 | 2.5.0-1 |
| cisofy | lynis | >= 0 < 2.5.0-1 | 2.5.0-1 |
| cisofy | lynis | >= 0 < 2.5.0-1 | 2.5.0-1 |
| cisofy | lynis | >= 0 < 2.5.0-1 | 2.5.0-1 |
| debian | lynis | < lynis 2.5.0-1 (bookworm) | lynis 2.5.0-1 (bookworm) |
CVSS provenance
nvdv3.07.8HIGHCVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
nvdv2.04.6MEDIUMAV:L/AC:L/Au:N/C:P/I:P/A:P
osv7.8HIGH
vendor_debian7.8LOW
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Debian
CVE-2017-8108: lynis - Unspecified tests in Lynis before 2.5.0 allow local users to write to arbitrary ...
vendor_debian·2017·CVSS 7.8
CVE-2017-8108 [HIGH] CVE-2017-8108: lynis - Unspecified tests in Lynis before 2.5.0 allow local users to write to arbitrary ...
Unspecified tests in Lynis before 2.5.0 allow local users to write to arbitrary files or possibly gain privileges via a symlink attack on a temporary file.
Scope: local
bookworm: resolved (fixed in 2.5.0-1)
bullseye: resolved (fixed in 2.5.0-1)
forky: resolved (fixed in 2.5.0-1)
sid: resolved (fixed in 2.5.0-1)
trixie: resolved (fixed in 2.5.0-1)
GHSA
GHSA-rm6c-xgjf-vhwg: Unspecified tests in Lynis before 2
ghsa_unreviewed·2022-05-13
CVE-2017-8108 [HIGH] CWE-59 GHSA-rm6c-xgjf-vhwg: Unspecified tests in Lynis before 2
Unspecified tests in Lynis before 2.5.0 allow local users to write to arbitrary files or possibly gain privileges via a symlink attack on a temporary file.
OSV
CVE-2017-8108: Unspecified tests in Lynis before 2
osv·2017-06-08·CVSS 7.8
CVE-2017-8108 [HIGH] CVE-2017-8108: Unspecified tests in Lynis before 2
Unspecified tests in Lynis before 2.5.0 allow local users to write to arbitrary files or possibly gain privileges via a symlink attack on a temporary file.
No detection rules found.
No public exploits indexed.
http://www.securityfocus.com/bid/99288https://cisofy.com/security/cve/cve-2017-8108/https://github.com/CISOfy/lynis/releases/tag/2.5.0https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/UJXMPYANXHI25NQZ36QMXNXANDRAA5YG/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/ZJHLLWNW7NASVXCK24YBSIUQQPWGCMB5/http://www.securityfocus.com/bid/99288https://cisofy.com/security/cve/cve-2017-8108/https://github.com/CISOfy/lynis/releases/tag/2.5.0https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/UJXMPYANXHI25NQZ36QMXNXANDRAA5YG/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/ZJHLLWNW7NASVXCK24YBSIUQQPWGCMB5/
2017-06-08
Published