postinst in twiki 4.1.2 allows local users to overwrite arbitrary files via a symlink attack on the /tmp/twiki temporary file. NOTE: the vendor disputes this vulnerability, stating "this bug is invalid.
Metrics
Affected Vendors & Products
References
History
No history.
MITRE
Status: PUBLISHED
Assigner: mitre
Published: 2008-11-07T19:00:00Z
Updated: 2024-09-17T03:48:37.462Z
Reserved: 2008-11-07T00:00:00Z
Link: CVE-2008-4998
Vulnrichment
No data.
NVD
Status : Modified
Published: 2008-11-07T19:36:24.070
Modified: 2024-11-21T00:53:02.140
Link: CVE-2008-4998
Redhat
No data.