// For flags

CVE-2008-0525

 

Severity Score

4.6
*CVSS v2

Exploit Likelihood

*EPSS

Affected Versions

*CPE

Public Exploits

0
*Multiple Sources

Exploited in Wild

-
*KEV

Decision

-
*SSVC
Descriptions

PatchLink Update client for Unix, as used by Novell ZENworks Patch Management Update Agent for Linux/Unix/Mac (LUM) 6.2094 through 6.4102 and other products, allows local users to (1) truncate arbitrary files via a symlink attack on the /tmp/patchlink.tmp file used by the logtrimmer script, and (2) execute arbitrary code via a symlink attack on the /tmp/plshutdown file used by the rebootTask script.

El cliente PatchLink Update para Unix, tal y como es usado por Novell ZENworks Patch Management Update Agent para Linux/Unix/Mac (LUM) versiones 6.2094 hasta 6.4102 y otros productos, permite a los usuarios locales (1) truncar archivos arbitrarios por medio de un ataque de tipo symlink en el archivo /tmp/patchlink.tmp usado por el script logtrimmer y (2) ejecutar código arbitrario por medio de un ataque tipo symlink en el archivo /tmp/plshutdown usado por el script rebootTask.

*Credits: N/A
CVSS Scores
Attack Vector
Local
Attack Complexity
Low
Authentication
None
Confidentiality
Partial
Integrity
Partial
Availability
Partial
* Common Vulnerability Scoring System
SSVC
  • Decision:-
Exploitation
-
Automatable
-
Tech. Impact
-
* Organization's Worst-case Scenario
Timeline
  • 2008-01-31 CVE Reserved
  • 2008-01-31 CVE Published
  • 2023-03-08 EPSS Updated
  • 2024-08-07 CVE Updated
  • ---------- Exploited in Wild
  • ---------- KEV Due Date
  • ---------- First Exploit
CWE
  • CWE-59: Improper Link Resolution Before File Access ('Link Following')
CAPEC
Affected Vendors, Products, and Versions
Vendor Product Version Other Status
Vendor Product Version Other Status <-- --> Vendor Product Version Other Status
Lumension Security
Search vendor "Lumension Security"
Patchlink Update
Search vendor "Lumension Security" for product "Patchlink Update"
6.2
Search vendor "Lumension Security" for product "Patchlink Update" and version "6.2"
linux
Affected
in Unix
Search vendor "Unix"
Unix
Search vendor "Unix" for product "Unix"
*-
Safe
Lumension Security
Search vendor "Lumension Security"
Patchlink Update
Search vendor "Lumension Security" for product "Patchlink Update"
6.2
Search vendor "Lumension Security" for product "Patchlink Update" and version "6.2"
mac
Affected
in Unix
Search vendor "Unix"
Unix
Search vendor "Unix" for product "Unix"
*-
Safe
Lumension Security
Search vendor "Lumension Security"
Patchlink Update
Search vendor "Lumension Security" for product "Patchlink Update"
6.2
Search vendor "Lumension Security" for product "Patchlink Update" and version "6.2"
unix
Affected
in Unix
Search vendor "Unix"
Unix
Search vendor "Unix" for product "Unix"
*-
Safe
Lumension Security
Search vendor "Lumension Security"
Patchlink Update
Search vendor "Lumension Security" for product "Patchlink Update"
6.3
Search vendor "Lumension Security" for product "Patchlink Update" and version "6.3"
linux
Affected
in Unix
Search vendor "Unix"
Unix
Search vendor "Unix" for product "Unix"
*-
Safe
Lumension Security
Search vendor "Lumension Security"
Patchlink Update
Search vendor "Lumension Security" for product "Patchlink Update"
6.3
Search vendor "Lumension Security" for product "Patchlink Update" and version "6.3"
mac
Affected
in Unix
Search vendor "Unix"
Unix
Search vendor "Unix" for product "Unix"
*-
Safe
Lumension Security
Search vendor "Lumension Security"
Patchlink Update
Search vendor "Lumension Security" for product "Patchlink Update"
6.3
Search vendor "Lumension Security" for product "Patchlink Update" and version "6.3"
unix
Affected
in Unix
Search vendor "Unix"
Unix
Search vendor "Unix" for product "Unix"
*-
Safe
Lumension Security
Search vendor "Lumension Security"
Patchlink Update
Search vendor "Lumension Security" for product "Patchlink Update"
6.4
Search vendor "Lumension Security" for product "Patchlink Update" and version "6.4"
linux
Affected
in Unix
Search vendor "Unix"
Unix
Search vendor "Unix" for product "Unix"
*-
Safe
Lumension Security
Search vendor "Lumension Security"
Patchlink Update
Search vendor "Lumension Security" for product "Patchlink Update"
6.4
Search vendor "Lumension Security" for product "Patchlink Update" and version "6.4"
mac
Affected
in Unix
Search vendor "Unix"
Unix
Search vendor "Unix" for product "Unix"
*-
Safe
Lumension Security
Search vendor "Lumension Security"
Patchlink Update
Search vendor "Lumension Security" for product "Patchlink Update"
6.4
Search vendor "Lumension Security" for product "Patchlink Update" and version "6.4"
unix
Affected
in Unix
Search vendor "Unix"
Unix
Search vendor "Unix" for product "Unix"
*-
Safe
Novell
Search vendor "Novell"
Zenworks Patch Management Update Agent
Search vendor "Novell" for product "Zenworks Patch Management Update Agent"
6.2
Search vendor "Novell" for product "Zenworks Patch Management Update Agent" and version "6.2"
linux
Affected
in Unix
Search vendor "Unix"
Unix
Search vendor "Unix" for product "Unix"
*-
Safe
Novell
Search vendor "Novell"
Zenworks Patch Management Update Agent
Search vendor "Novell" for product "Zenworks Patch Management Update Agent"
6.2
Search vendor "Novell" for product "Zenworks Patch Management Update Agent" and version "6.2"
mac
Affected
in Unix
Search vendor "Unix"
Unix
Search vendor "Unix" for product "Unix"
*-
Safe
Novell
Search vendor "Novell"
Zenworks Patch Management Update Agent
Search vendor "Novell" for product "Zenworks Patch Management Update Agent"
6.2
Search vendor "Novell" for product "Zenworks Patch Management Update Agent" and version "6.2"
unix
Affected
in Unix
Search vendor "Unix"
Unix
Search vendor "Unix" for product "Unix"
*-
Safe
Novell
Search vendor "Novell"
Zenworks Patch Management Update Agent
Search vendor "Novell" for product "Zenworks Patch Management Update Agent"
6.3
Search vendor "Novell" for product "Zenworks Patch Management Update Agent" and version "6.3"
linux
Affected
in Unix
Search vendor "Unix"
Unix
Search vendor "Unix" for product "Unix"
*-
Safe
Novell
Search vendor "Novell"
Zenworks Patch Management Update Agent
Search vendor "Novell" for product "Zenworks Patch Management Update Agent"
6.3
Search vendor "Novell" for product "Zenworks Patch Management Update Agent" and version "6.3"
mac
Affected
in Unix
Search vendor "Unix"
Unix
Search vendor "Unix" for product "Unix"
*-
Safe
Novell
Search vendor "Novell"
Zenworks Patch Management Update Agent
Search vendor "Novell" for product "Zenworks Patch Management Update Agent"
6.3
Search vendor "Novell" for product "Zenworks Patch Management Update Agent" and version "6.3"
unix
Affected
in Unix
Search vendor "Unix"
Unix
Search vendor "Unix" for product "Unix"
*-
Safe
Novell
Search vendor "Novell"
Zenworks Patch Management Update Agent
Search vendor "Novell" for product "Zenworks Patch Management Update Agent"
6.4
Search vendor "Novell" for product "Zenworks Patch Management Update Agent" and version "6.4"
linux
Affected
in Unix
Search vendor "Unix"
Unix
Search vendor "Unix" for product "Unix"
*-
Safe
Novell
Search vendor "Novell"
Zenworks Patch Management Update Agent
Search vendor "Novell" for product "Zenworks Patch Management Update Agent"
6.4
Search vendor "Novell" for product "Zenworks Patch Management Update Agent" and version "6.4"
mac
Affected
in Unix
Search vendor "Unix"
Unix
Search vendor "Unix" for product "Unix"
*-
Safe
Novell
Search vendor "Novell"
Zenworks Patch Management Update Agent
Search vendor "Novell" for product "Zenworks Patch Management Update Agent"
6.4
Search vendor "Novell" for product "Zenworks Patch Management Update Agent" and version "6.4"
unix
Affected
in Unix
Search vendor "Unix"
Unix
Search vendor "Unix" for product "Unix"
*-
Safe