CVE-2008-2266
16.05.2008, 12:54
uulib/uunconc.c in UUDeview 0.5.20, as used in nzbget before 0.3.0 and possibly other products, allows local users to overwrite arbitrary files via a symlink attack on a temporary filename generated by the tempnam function. NOTE: this may be a CVE-2004-2265 regression.
| Vendor | Product | Version |
|---|---|---|
| nzbget | nzbget | 𝑥 ≤ 0.2.2 |
| nzbget | nzbget | 0.1.0a:a |
| nzbget | nzbget | 0.1.1 |
| nzbget | nzbget | 0.1.2 |
| nzbget | nzbget | 0.2.0 |
| nzbget | nzbget | 0.2.1 |
| uudeview | uudeview | 0.5.20 |
𝑥
= Vulnerable software versions
Debian Releases
Debian Product | |||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|
| libconvert-uulib-perl |
| ||||||||||
| pan |
| ||||||||||
| uudeview |
|
Ubuntu Releases
Ubuntu Product | |||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| libconvert-uulib-perl |
| ||||||||||||||||||||||
| uudeview |
|
References