Files
CVEs-PoC/2008/CVE-2008-4943.md
T
2024-06-18 02:51:15 +02:00

18 lines
794 B
Markdown

### [CVE-2008-4943](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-4943)
![](https://img.shields.io/static/v1?label=Product&message=n%2Fa&color=blue)
![](https://img.shields.io/static/v1?label=Version&message=n%2Fa&color=blue)
![](https://img.shields.io/static/v1?label=Vulnerability&message=n%2Fa&color=brighgreen)
### Description
bulmages-servers 0.11.1 allows local users to overwrite arbitrary files via a symlink attack on the (a) /tmp/error.txt, (b) /tmp/errores.txt, and possibly other temporary files, related to the (1) creabulmafact, (2) creabulmacont, and possibly (3) actualizabulmacont, (4) installbulmages-db, and (5) actualizabulmafact scripts.
### POC
#### Reference
- https://bugs.gentoo.org/show_bug.cgi?id=235770
#### Github
No PoCs found on GitHub currently.