CVE-2008-5312

mailscanner 4.55.10 and other versions before 4.74.16-1 might allow local users to overwrite arbitrary files via a symlink attack on certain temporary files used by the (1) f-prot-autoupdate, (2) clamav-autoupdate, (3) panda-autoupdate.new, (4) trend-autoupdate.new, and (5) rav-autoupdate.new scripts in /etc/MailScanner/autoupdate/, a different vulnerability than CVE-2008-5140.
Link Following
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
6.9 UNKNOWN
LOCAL
MEDIUM
AV:L/AC:M/Au:N/C:C/I:C/A:C
mitreCNA
---
---
CVEADP
---
---
Base Score
CVSS 3.x
EPSS Score
Percentile: 4%
VendorProductVersion
mailscannermailscanner
4.55.10
mailscannermailscanner
4.56.8-1
mailscannermailscanner
4.57.7-1
mailscannermailscanner
4.58.9-1
mailscannermailscanner
4.59.4-2
mailscannermailscanner
4.60.8-1
mailscannermailscanner
4.61.7-2
mailscannermailscanner
4.62.9-3
mailscannermailscanner
4.63.8-1
mailscannermailscanner
4.64.3-2
mailscannermailscanner
4.65.3-1
mailscannermailscanner
4.66.5-3
mailscannermailscanner
4.67.6-1
mailscannermailscanner
4.68.8
mailscannermailscanner
4.68.8-1
mailscannermailscanner
4.69.9-3
mailscannermailscanner
4.70.7-1
mailscannermailscanner
4.71.10-1
mailscannermailscanner
4.72.5-1
mailscannermailscanner
4.73.4-2
𝑥
= Vulnerable software versions
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
mailscanner
oneiric
dne
natty
not-affected
maverick
not-affected
lucid
not-affected
karmic
not-affected
jaunty
not-affected
intrepid
ignored
hardy
ignored
gutsy
ignored
dapper
ignored