VULNERABILITY INTELLIGENCE

CVE-2008-4580

CVSS score7.2 HIGH
EPSS probability0.36%
CISA KEVNot currently listed
Published2008-10-15
Last modified2026-06-16
CVSS vectorAV:L/AC:L/Au:N/C:C/I:C/A:C

Description

fence_manual, as used in fence 2.02.00-r1 and possibly cman, allows local users to modify arbitrary files via a symlink attack on the fence_manual.fifo temporary file.

Weakness classification

  • CWE-59: Improper Link Resolution Before File Access ('Link Following')

Primary references