CVE-2008-3524

Properties

Published:
28.09.2008
Updated:
29.09.2008
Patch available:

Vulnerability description

rc.sysinit in initscripts before 8.76.3-1 in Fedora 9 allows local users to delete arbitrary files via a symlink attack on a file or directory under (1) /var/lock or (2) /var/run.

References:

FEDORA: https://www.redhat.com/archives/fedora-package-announce/2008-September/msg01135.html
CONFIRM: https://bugzilla.redhat.com/show_bug.cgi?id=458652
CONFIRM: https://bugzilla.redhat.com/show_bug.cgi?id=458504
XF: http://xforce.iss.net/xforce/xfdb/45402
BID: http://www.securityfocus.com/bid/31385
SECUNIA: http://secunia.com/advisories/32037