// For flags

CVE-2008-2266

 

Severity Score

4.4
*CVSS v2

Exploit Likelihood

*EPSS

Affected Versions

*CPE

Public Exploits

0
*Multiple Sources

Exploited in Wild

-
*KEV

Decision

-
*SSVC
Descriptions

uulib/uunconc.c in UUDeview 0.5.20, as used in nzbget before 0.3.0 and possibly other products, allows local users to overwrite arbitrary files via a symlink attack on a temporary filename generated by the tempnam function. NOTE: this may be a CVE-2004-2265 regression.

En la biblioteca uulib/uunconc.c en UUDeview versión 0.5.20, como es usado en nzbget versiones anteriores a 0.3.0 y posiblemente en otros productos, permite a usuarios locales sobrescribir archivos arbitrarios por medio de un ataque de tipo symlink sobre un nombre de archivo temporal generado por la función tempnam. NOTA: este puede ser una regresión de CVE-2004-2265.

*Credits: N/A
CVSS Scores
Attack Vector
Local
Attack Complexity
Medium
Authentication
None
Confidentiality
Partial
Integrity
Partial
Availability
Partial
* Common Vulnerability Scoring System
SSVC
  • Decision:-
Exploitation
-
Automatable
-
Tech. Impact
-
* Organization's Worst-case Scenario
Timeline
  • 2008-05-16 CVE Reserved
  • 2008-05-16 CVE Published
  • 2023-03-08 EPSS Updated
  • 2024-08-07 CVE Updated
  • ---------- Exploited in Wild
  • ---------- KEV Due Date
  • ---------- First Exploit
CWE
  • CWE-59: Improper Link Resolution Before File Access ('Link Following')
CAPEC
Affected Vendors, Products, and Versions
Vendor Product Version Other Status
Vendor Product Version Other Status <-- --> Vendor Product Version Other Status
Nzbget
Search vendor "Nzbget"
Nzbget
Search vendor "Nzbget" for product "Nzbget"
<= 0.2.2
Search vendor "Nzbget" for product "Nzbget" and version " <= 0.2.2"
-
Affected
Nzbget
Search vendor "Nzbget"
Nzbget
Search vendor "Nzbget" for product "Nzbget"
0.1.0a
Search vendor "Nzbget" for product "Nzbget" and version "0.1.0a"
-
Affected
Nzbget
Search vendor "Nzbget"
Nzbget
Search vendor "Nzbget" for product "Nzbget"
0.1.1
Search vendor "Nzbget" for product "Nzbget" and version "0.1.1"
-
Affected
Nzbget
Search vendor "Nzbget"
Nzbget
Search vendor "Nzbget" for product "Nzbget"
0.1.2
Search vendor "Nzbget" for product "Nzbget" and version "0.1.2"
-
Affected
Nzbget
Search vendor "Nzbget"
Nzbget
Search vendor "Nzbget" for product "Nzbget"
0.2.0
Search vendor "Nzbget" for product "Nzbget" and version "0.2.0"
-
Affected
Nzbget
Search vendor "Nzbget"
Nzbget
Search vendor "Nzbget" for product "Nzbget"
0.2.1
Search vendor "Nzbget" for product "Nzbget" and version "0.2.1"
-
Affected
Uudeview
Search vendor "Uudeview"
Uudeview
Search vendor "Uudeview" for product "Uudeview"
0.5.20
Search vendor "Uudeview" for product "Uudeview" and version "0.5.20"
-
Affected