CVE-2008-1614

EUVD-2008-1615
suPHP before 0.6.3 allows local users to gain privileges via (1) a race condition that involves multiple symlink changes to point a file owned by a different user, or (2) a symlink to the directory of a different user, which is used to determine privileges.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
4.3 UNKNOWN
LOCAL
LOW
AV:L/AC:L/Au:S/C:P/I:P/A:P
Base Score
CVSS 3.x
EPSS Score
Percentile: 19%
Affected Products (NVD)
VendorProductVersion
sebastian_marschingsuphp
𝑥
≤ 0.6.2
𝑥
= Vulnerable software versions
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
suphp
dapper
ignored
edgy
ignored
feisty
ignored
gutsy
ignored
hardy
Fixed 0.6.2-2ubuntu1
released
intrepid
Fixed 0.6.2-2ubuntu1
released
jaunty
Fixed 0.6.2-2ubuntu1
released
karmic
Fixed 0.6.2-2ubuntu1
released
Common Weakness Enumeration