VULNERABILITY INTELLIGENCE
CVE-2008-4580
CVSS score7.2 HIGH
EPSS probability0.36%
CISA KEVNot currently listed
Published2008-10-15
Last modified2026-06-16
CVSS vectorAV:L/AC:L/Au:N/C:C/I:C/A:C
Description
fence_manual, as used in fence 2.02.00-r1 and possibly cman, allows local users to modify arbitrary files via a symlink attack on the fence_manual.fifo temporary file.
Weakness classification
- CWE-59: Improper Link Resolution Before File Access ('Link Following')