CVE-2008-6552

Red Hat Cluster Project 2.x allows local users to modify or overwrite arbitrary files via symlink attacks on files in /tmp, involving unspecified components in Resource Group Manager (aka rgmanager) before 2.03.09-1, gfs2-utils before 2.03.09-1, and CMAN - The Cluster Manager before 2.03.09-1 on Fedora 9.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:redhat:cluster_project:2.00.00:*:*:*:*:*:*:*
cpe:2.3:a:redhat:cluster_project:2.01.00:*:*:*:*:*:*:*
cpe:2.3:a:redhat:cluster_project:2.02.00:*:*:*:*:*:*:*
cpe:2.3:a:redhat:cluster_project:2.03.00:*:*:*:*:*:*:*
cpe:2.3:a:redhat:cluster_project:2.03.01:*:*:*:*:*:*:*
cpe:2.3:a:redhat:cluster_project:2.03.03:*:*:*:*:*:*:*
cpe:2.3:a:redhat:cluster_project:2.03.04:*:*:*:*:*:*:*
cpe:2.3:a:redhat:cluster_project:2.03.05:*:*:*:*:*:*:*
cpe:2.3:a:redhat:cluster_project:2.03.7:*:*:*:*:*:*:*
cpe:2.3:a:redhat:cluster_project:2.03.08:*:*:*:*:*:*:*
cpe:2.3:a:redhat:cluster_project:2.03.09:*:*:*:*:*:*:*
cpe:2.3:a:redhat:cluster_project:2.03.10:*:*:*:*:*:*:*
cpe:2.3:a:redhat:cluster_project:2.03.11:*:*:*:*:*:*:*
cpe:2.3:a:redhat:cluster_project:2.99.00:*:*:*:*:*:*:*
cpe:2.3:a:redhat:cluster_project:2.99.01:*:*:*:*:*:*:*
cpe:2.3:a:redhat:cluster_project:2.99.02:*:*:*:*:*:*:*
cpe:2.3:a:redhat:cluster_project:2.99.03:*:*:*:*:*:*:*
cpe:2.3:a:redhat:cluster_project:2.99.04:*:*:*:*:*:*:*
cpe:2.3:a:redhat:cluster_project:2.99.05:*:*:*:*:*:*:*
cpe:2.3:a:redhat:cluster_project:2.99.06:*:*:*:*:*:*:*
cpe:2.3:a:redhat:cluster_project:2.99.07:*:*:*:*:*:*:*
cpe:2.3:a:redhat:cluster_project:2.99.08:*:*:*:*:*:*:*
cpe:2.3:a:redhat:cluster_project:2.99.09:*:*:*:*:*:*:*
cpe:2.3:a:redhat:cluster_project:2.99.10:*:*:*:*:*:*:*
cpe:2.3:a:redhat:cluster_project:2.99.11:*:*:*:*:*:*:*
cpe:2.3:a:redhat:cluster_project:2.99.12:*:*:*:*:*:*:*
cpe:2.3:a:redhat:cluster_project:2.99.13:*:*:*:*:*:*:*

Configuration 2 (hide)

AND
OR cpe:2.3:a:redhat:cman:2.03.03-1:*:*:*:*:*:*:*
cpe:2.3:a:redhat:cman:2.03.04-1:*:*:*:*:*:*:*
cpe:2.3:a:redhat:cman:2.03.05-1:*:*:*:*:*:*:*
cpe:2.3:a:redhat:cman:2.03.07-1:*:*:*:*:*:*:*
cpe:2.3:a:redhat:cman:2.03.08-1:*:*:*:*:*:*:*
cpe:2.3:a:redhat:rgmanager:2.03.03-1:*:*:*:*:*:*:*
cpe:2.3:a:redhat:rgmanager:2.03.04-1:*:*:*:*:*:*:*
cpe:2.3:a:redhat:rgmanager:2.03.05-1:*:*:*:*:*:*:*
cpe:2.3:a:redhat:rgmanager:2.03.07-1:*:*:*:*:*:*:*
cpe:2.3:a:redhat:rgmanager:2.03.08-1:*:*:*:*:*:*:*
cpe:2.3:o:fedoraproject:fedora:9:*:*:*:*:*:*:*
OR cpe:2.3:a:redhat:gfs2-utils:2.03.03-1:*:*:*:*:*:*:*
cpe:2.3:a:redhat:gfs2-utils:2.03.04-1:*:*:*:*:*:*:*
cpe:2.3:a:redhat:gfs2-utils:2.03.05-1:*:*:*:*:*:*:*
cpe:2.3:a:redhat:gfs2-utils:2.03.07-1:*:*:*:*:*:*:*
cpe:2.3:a:redhat:gfs2-utils:22.03.08-1:*:*:*:*:*:*:*

History

No history.

Information

Published : 2009-03-30 16:30

Updated : 2023-12-10 10:51


NVD link : CVE-2008-6552

Mitre link : CVE-2008-6552

CVE.ORG link : CVE-2008-6552


JSON object : View

Products Affected

fedoraproject

  • fedora

redhat

  • rgmanager
  • cman
  • cluster_project
  • gfs2-utils
CWE
CWE-59

Improper Link Resolution Before File Access ('Link Following')