4.6

CVE-2008-0525

PatchLink Update client for Unix, as used by Novell ZENworks Patch Management Update Agent for Linux/Unix/Mac (LUM) 6.2094 through 6.4102 and other products, allows local users to (1) truncate arbitrary files via a symlink attack on the /tmp/patchlink.tmp file used by the logtrimmer script, and (2) execute arbitrary code via a symlink attack on the /tmp/plshutdown file used by the rebootTask script.

Data is provided by the National Vulnerability Database (NVD)
Lumension SecurityPatchlink Update Version6.2 Editionlinux
   UnixUnix
Lumension SecurityPatchlink Update Version6.2 Editionmac
   UnixUnix
Lumension SecurityPatchlink Update Version6.2 Editionunix
   UnixUnix
Lumension SecurityPatchlink Update Version6.3 Editionlinux
   UnixUnix
Lumension SecurityPatchlink Update Version6.3 Editionmac
   UnixUnix
Lumension SecurityPatchlink Update Version6.3 Editionunix
   UnixUnix
Lumension SecurityPatchlink Update Version6.4 Editionlinux
   UnixUnix
Lumension SecurityPatchlink Update Version6.4 Editionmac
   UnixUnix
Lumension SecurityPatchlink Update Version6.4 Editionunix
   UnixUnix
NovellZenworks Patch Management Update Agent Version6.2 Editionlinux
   UnixUnix
NovellZenworks Patch Management Update Agent Version6.2 Editionmac
   UnixUnix
NovellZenworks Patch Management Update Agent Version6.2 Editionunix
   UnixUnix
NovellZenworks Patch Management Update Agent Version6.3 Editionlinux
   UnixUnix
NovellZenworks Patch Management Update Agent Version6.3 Editionmac
   UnixUnix
NovellZenworks Patch Management Update Agent Version6.3 Editionunix
   UnixUnix
NovellZenworks Patch Management Update Agent Version6.4 Editionlinux
   UnixUnix
NovellZenworks Patch Management Update Agent Version6.4 Editionmac
   UnixUnix
NovellZenworks Patch Management Update Agent Version6.4 Editionunix
   UnixUnix
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Type Source Score Percentile
EPSS FIRST.org 0.1% 0.252
CVSS Metriken
Source Base Score Exploit Score Impact Score Vector string
nvd@nist.gov 4.6 3.9 6.4
AV:L/AC:L/Au:N/C:P/I:P/A:P
CWE-59 Improper Link Resolution Before File Access ('Link Following')

The product attempts to access a file based on the filename, but it does not properly prevent that filename from identifying a link or shortcut that resolves to an unintended resource.