CVE-2008-2266
16.05.2008, 12:54
uulib/uunconc.c in UUDeview 0.5.20, as used in nzbget before 0.3.0 and possibly other products, allows local users to overwrite arbitrary files via a symlink attack on a temporary filename generated by the tempnam function. NOTE: this may be a CVE-2004-2265 regression.
Vendor | Product | Version |
---|---|---|
nzbget | nzbget | 𝑥 ≤ 0.2.2 |
nzbget | nzbget | 0.1.0a:a |
nzbget | nzbget | 0.1.1 |
nzbget | nzbget | 0.1.2 |
nzbget | nzbget | 0.2.0 |
nzbget | nzbget | 0.2.1 |
uudeview | uudeview | 0.5.20 |
𝑥
= Vulnerable software versions

Debian Releases
Debian Product | |||||||||||
---|---|---|---|---|---|---|---|---|---|---|---|
libconvert-uulib-perl |
| ||||||||||
pan |
| ||||||||||
uudeview |
|

Ubuntu Releases
Ubuntu Product | |||||||||||||||||||||||
---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
libconvert-uulib-perl |
| ||||||||||||||||||||||
uudeview |
|
References