CVE-2008-4953

Publication date 5 November 2008

Last updated 4 August 2025


Ubuntu priority

Negligible

Why this priority?

Description

firehol in firehol 1.256 allows local users to overwrite arbitrary files via a symlink attack on (1) /tmp/.firehol-tmp-#####-*-* and (2) /tmp/firehol.conf temporary files. NOTE: the vendor disputes this vulnerability, stating that an attack "would require an attacker to create 1073741824*PID-RANGE symlinks.

Read the notes from the security team

Status

Package Ubuntu Release Status
firehol 9.10 karmic Ignored
9.04 jaunty Ignored
8.10 intrepid Ignored
8.04 LTS hardy Ignored
7.10 gutsy Ignored end of life, was needed
6.06 LTS dapper Ignored end of life

Notes


mdeslaur

disputed because attack is unfeasible


Access our resources on patching vulnerabilities