CVE-2008-1078

NameCVE-2008-1078
Descriptionexpn in the am-utils and net-fs packages for Gentoo, rPath Linux, and other distributions, allows local users to overwrite arbitrary files via a symlink attack on the expn[PID] temporary file. NOTE: this is the same issue as CVE-2003-0308.1.
SourceCVE (at NVD; CERT, LWN, oss-sec, fulldisc, bugtraq, EDB, Metasploit, Red Hat, Ubuntu, Gentoo, SUSE bugzilla/CVE, Mageia, GitHub code/issues, web search, more)
NVD severityhigh

The information below is based on the following data on fixed versions.

PackageTypeReleaseFixed VersionUrgencyOriginDebian Bugs
am-utilssource(unstable)(not affected)

Notes

- am-utils <not-affected> (Affected code not present in the binary package)
sendmail includes a copy of the script, which has been fixed since
several years

Search for package or bug name: Reporting problems