CVE-2008-4998

Publication date 7 November 2008

Last updated 4 August 2025


Ubuntu priority

Description

postinst in twiki 4.1.2 allows local users to overwrite arbitrary files via a symlink attack on the /tmp/twiki temporary file. NOTE: the vendor disputes this vulnerability, stating "this bug is invalid.

Status

Package Ubuntu Release Status
twiki 11.10 oneiric Not in release
11.04 natty Not in release
10.10 maverick Not in release
10.04 LTS lucid Not in release
9.10 karmic
Not affected
9.04 jaunty
Not affected
8.10 intrepid
Fixed 1:4.1.2-3.2ubuntu1.1
8.04 LTS hardy Ignored end of life
7.10 gutsy Ignored end of life, was needs-triage
6.06 LTS dapper Ignored end of life

Patch details

For informational purposes only. We recommend not to cherry-pick updates. How can I get the fixes?

Package Patch details
twiki

Access our resources on patching vulnerabilities