// For flags

CVE-2008-4832

 

Severity Score

6.9
*CVSS v2

Exploit Likelihood

*EPSS

Affected Versions

*CPE

Public Exploits

0
*Multiple Sources

Exploited in Wild

-
*KEV

Decision

-
*SSVC
Descriptions

rc.sysinit in initscripts 8.12-8.21 and 8.56.15-0.1 on rPath allows local users to delete arbitrary files via a symlink attack on a directory under (1) /var/lock or (2) /var/run. NOTE: this issue exists because of a race condition in an incorrect fix for CVE-2008-3524. NOTE: exploitation may require an unusual scenario in which rc.sysinit is executed other than at boot time.

rc.sysinit en el paquete initscripts en sus versiones 8.12-8.21 y 8.56.15-0.1 de rPath permite a usuarios locales borrar archivos arbitrarios a través de un ataque de seguimiento de enlace simbólicos sobre un directorio bajo (1) /var/lock o (2) /var/run. NOTA: Este problema existe debido a una condición de carrera en una incorrecta solución a la vulnerabilidad CVE-2008-3524. NOTA: La explotación podrá exigir un escenario inusual en el que se ejecuta rc.sysinit en un momento distinto al arranque del sistema.

*Credits: N/A
CVSS Scores
Attack Vector
Local
Attack Complexity
Medium
Authentication
None
Confidentiality
Complete
Integrity
Complete
Availability
Complete
* Common Vulnerability Scoring System
SSVC
  • Decision:-
Exploitation
-
Automatable
-
Tech. Impact
-
* Organization's Worst-case Scenario
Timeline
  • 2008-10-31 CVE Reserved
  • 2008-11-17 CVE Published
  • 2023-03-08 EPSS Updated
  • 2024-08-07 CVE Updated
  • ---------- Exploited in Wild
  • ---------- KEV Due Date
  • ---------- First Exploit
CWE
  • CWE-59: Improper Link Resolution Before File Access ('Link Following')
CAPEC
Affected Vendors, Products, and Versions
Vendor Product Version Other Status
Vendor Product Version Other Status <-- --> Vendor Product Version Other Status
Rpath
Search vendor "Rpath"
Initscripts
Search vendor "Rpath" for product "Initscripts"
8.12-8.21
Search vendor "Rpath" for product "Initscripts" and version "8.12-8.21"
-
Affected
in Rpath
Search vendor "Rpath"
Appliance Platform Linux Service
Search vendor "Rpath" for product "Appliance Platform Linux Service"
1
Search vendor "Rpath" for product "Appliance Platform Linux Service" and version "1"
-
Safe
Rpath
Search vendor "Rpath"
Initscripts
Search vendor "Rpath" for product "Initscripts"
8.12-8.21
Search vendor "Rpath" for product "Initscripts" and version "8.12-8.21"
-
Affected
in Rpath
Search vendor "Rpath"
Appliance Platform Linux Service
Search vendor "Rpath" for product "Appliance Platform Linux Service"
2
Search vendor "Rpath" for product "Appliance Platform Linux Service" and version "2"
-
Safe
Rpath
Search vendor "Rpath"
Initscripts
Search vendor "Rpath" for product "Initscripts"
8.12-8.21
Search vendor "Rpath" for product "Initscripts" and version "8.12-8.21"
-
Affected
in Rpath
Search vendor "Rpath"
Linux
Search vendor "Rpath" for product "Linux"
1
Search vendor "Rpath" for product "Linux" and version "1"
-
Safe
Rpath
Search vendor "Rpath"
Initscripts
Search vendor "Rpath" for product "Initscripts"
8.12-8.21
Search vendor "Rpath" for product "Initscripts" and version "8.12-8.21"
-
Affected
in Rpath
Search vendor "Rpath"
Linux
Search vendor "Rpath" for product "Linux"
2
Search vendor "Rpath" for product "Linux" and version "2"
-
Safe
Rpath
Search vendor "Rpath"
Initscripts
Search vendor "Rpath" for product "Initscripts"
8.56.15-0.1
Search vendor "Rpath" for product "Initscripts" and version "8.56.15-0.1"
-
Affected
in Rpath
Search vendor "Rpath"
Appliance Platform Linux Service
Search vendor "Rpath" for product "Appliance Platform Linux Service"
1
Search vendor "Rpath" for product "Appliance Platform Linux Service" and version "1"
-
Safe
Rpath
Search vendor "Rpath"
Initscripts
Search vendor "Rpath" for product "Initscripts"
8.56.15-0.1
Search vendor "Rpath" for product "Initscripts" and version "8.56.15-0.1"
-
Affected
in Rpath
Search vendor "Rpath"
Appliance Platform Linux Service
Search vendor "Rpath" for product "Appliance Platform Linux Service"
2
Search vendor "Rpath" for product "Appliance Platform Linux Service" and version "2"
-
Safe
Rpath
Search vendor "Rpath"
Initscripts
Search vendor "Rpath" for product "Initscripts"
8.56.15-0.1
Search vendor "Rpath" for product "Initscripts" and version "8.56.15-0.1"
-
Affected
in Rpath
Search vendor "Rpath"
Linux
Search vendor "Rpath" for product "Linux"
1
Search vendor "Rpath" for product "Linux" and version "1"
-
Safe
Rpath
Search vendor "Rpath"
Initscripts
Search vendor "Rpath" for product "Initscripts"
8.56.15-0.1
Search vendor "Rpath" for product "Initscripts" and version "8.56.15-0.1"
-
Affected
in Rpath
Search vendor "Rpath"
Linux
Search vendor "Rpath" for product "Linux"
2
Search vendor "Rpath" for product "Linux" and version "2"
-
Safe