rc.sysinit in initscripts before 8.76.3-1 on Fedora 9 and other Linux platforms allows local users to delete arbitrary files via a symlink attack on a file or directory under (1) /var/lock or (2) /var/run.
                
            References
                    Configurations
                    Configuration 1 (hide)
| AND | 
 
 | 
History
                    21 Nov 2024, 00:49
| Type | Values Removed | Values Added | 
|---|---|---|
| References | () http://secunia.com/advisories/32037 - Vendor Advisory | |
| References | () http://secunia.com/advisories/32710 - | |
| References | () http://wiki.rpath.com/wiki/Advisories:rPSA-2008-0318 - | |
| References | () http://www.securityfocus.com/bid/31385 - | |
| References | () https://bugzilla.redhat.com/show_bug.cgi?id=458504 - | |
| References | () https://bugzilla.redhat.com/show_bug.cgi?id=458652 - | |
| References | () https://exchange.xforce.ibmcloud.com/vulnerabilities/45402 - | |
| References | () https://issues.rpath.com/browse/RPL-2857 - | |
| References | () https://www.redhat.com/archives/fedora-package-announce/2008-September/msg01135.html - | 
Information
                Published : 2008-09-29 17:17
Updated : 2025-04-09 00:30
NVD link : CVE-2008-3524
Mitre link : CVE-2008-3524
CVE.ORG link : CVE-2008-3524
JSON object : View
Products Affected
                redhat
- initscripts
- fedora
CWE
                
                    
                        
                        CWE-59
                        
            Improper Link Resolution Before File Access ('Link Following')
