CVE-2007-4998

NameCVE-2007-4998
SourceCVE (at NVD; RH)
Descriptioncp, when running with an option to preserve symlinks on multiple OSes, allows local, user-assisted attackers to overwrite arbitrary files via a symlink attack using crafted directories containing multiple source files that are copied to the same destination.
NVD severitymedium (attack range: local, user-initiated)
Debian/oldstablenot vulnerable.
Debian/stablenot vulnerable.
Debian/testingnot vulnerable.
Debian/unstablenot vulnerable.

Vulnerable and fixed packages

The table below lists information on source packages.

Source PackageReleaseVersionStatus
coreutils (PTS)lenny6.10-6fixed
squeeze8.5-1fixed
wheezy, sid8.13-3fixed

The information above is based on the following data on fixed versions.

PackageTypeReleaseFixed VersionUrgencyOriginDebian Bugs
coreutilssource(unstable)4.1.2medium

Notes

https://bugzilla.redhat.com/show_bug.cgi?id=356471

Search for package or bug name: Reporting problems

Home - Testing Security Team - Debian Security - Imprint