CVE-2008-4579

Severity CVSS v4.0:
Pending analysis
Type:
CWE-59 Link Following
Publication date:
15/10/2008
Last modified:
09/04/2025

Description

The (1) fence_apc and (2) fence_apc_snmp programs, as used in (a) fence 2.02.00-r1 and possibly (b) cman, when running in verbose mode, allows local users to append to arbitrary files via a symlink attack on the apclog temporary file.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:gentoo:cman:2.02.00:r1:*:*:*:*:*:*
cpe:2.3:a:gentoo:fence:2.02.00:r1:*:*:*:*:*:*