CVE-2008-4108

EUVD-2008-4091
Tools/faqwiz/move-faqwiz.sh (aka the generic FAQ wizard moving tool) in Python 2.4.5 might allow local users to overwrite arbitrary files via a symlink attack on a tmp$RANDOM.tmp temporary file.  NOTE: there may not be common usage scenarios in which tmp$RANDOM.tmp is located in an untrusted directory.
Link Following
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
7.2 UNKNOWN
LOCAL
LOW
AV:L/AC:L/Au:N/C:C/I:C/A:C
Base Score
CVSS 3.x
EPSS Score
Percentile: 8%
Affected Products (NVD)
VendorProductVersion
python_software_foundationpython
2.4.5
𝑥
= Vulnerable software versions
Debian logo
Debian Releases
Debian Product
Codename
python-defaults
bullseye
unimportant
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
python2.4
dapper
ignored
hardy
ignored
karmic
not-affected
lucid
dne
maverick
dne
natty
dne
oneiric
dne
precise
dne
python2.5
dapper
dne
hardy
ignored
karmic
not-affected
lucid
dne
maverick
dne
natty
dne
oneiric
dne
precise
dne
python2.6
dapper
dne
hardy
dne
karmic
not-affected
lucid
not-affected
maverick
not-affected
natty
not-affected
oneiric
not-affected
precise
dne