CVE-2008-4997

Publication date 7 November 2008

Last updated 4 August 2025


Ubuntu priority

Negligible

Why this priority?

Description

dfxml-invoice in datafreedom-perl 0.1.7 allows local users to overwrite arbitrary files via a symlink attack on the /tmp/zenity temporary file. NOTE: the vendor disputes this vulnerability, stating that the vector is solely "an EXAMPLE used in the manpage.

Read the notes from the security team

Status

Package Ubuntu Release Status
pilot-qof 9.10 karmic Ignored
9.04 jaunty Ignored
8.10 intrepid Ignored
8.04 LTS hardy Ignored
7.10 gutsy Ignored end of life, was needed
6.06 LTS dapper Ignored end of life

Notes


mdeslaur

not exploitable, ignored


Access our resources on patching vulnerabilities