CVE-2008-4108

Tools/faqwiz/move-faqwiz.sh (aka the generic FAQ wizard moving tool) in Python 2.4.5 might allow local users to overwrite arbitrary files via a symlink attack on a tmp$RANDOM.tmp temporary file.  NOTE: there may not be common usage scenarios in which tmp$RANDOM.tmp is located in an untrusted directory.
Link Following
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
7.2 UNKNOWN
LOCAL
LOW
AV:L/AC:L/Au:N/C:C/I:C/A:C
mitreCNA
---
---
CVEADP
---
---
Base Score
CVSS 3.x
EPSS Score
Percentile: 17%
VendorProductVersion
python_software_foundationpython
2.4.5
𝑥
= Vulnerable software versions
Debian logo
Debian Releases
Debian Product
Codename
python-defaults
bullseye
unimportant
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
python2.4
precise
dne
oneiric
dne
natty
dne
maverick
dne
lucid
dne
karmic
not-affected
hardy
ignored
dapper
ignored
python2.5
precise
dne
oneiric
dne
natty
dne
maverick
dne
lucid
dne
karmic
not-affected
hardy
ignored
dapper
dne
python2.6
precise
dne
oneiric
not-affected
natty
not-affected
maverick
not-affected
lucid
not-affected
karmic
not-affected
hardy
dne
dapper
dne