CVE-2008-5380

medium

Description

gpsdrive (aka gpsdrive-scripts) 2.09 allows local users to overwrite arbitrary files via a symlink attack on an (a) /tmp/geo#####, a (b) /tmp/geocaching.loc, a (c) /tmp/geo#####.*, or a (d) /tmp/geo.* temporary file, related to the (1) geo-code and (2) geo-nearest scripts, different vectors than CVE-2008-4959.

References

https://www.redhat.com/archives/fedora-package-announce/2009-February/msg00187.html

http://secunia.com/advisories/33825

http://secunia.com/advisories/31694

http://lists.debian.org/debian-devel/2008/08/msg00285.html

Details

Source: Mitre, NVD

Published: 2008-12-08

Updated: 2009-08-19

Risk Information

CVSS v2

Base Score: 6.9

Vector: CVSS2#AV:L/AC:M/Au:N/C:C/I:C/A:C

Severity: Medium

CVSS v3

Base Score: 5.5

Vector: CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N

Severity: Medium