CVE Vulnerabilities

CVE-2008-6552

Improper Link Resolution Before File Access ('Link Following')

Published: Mar 30, 2009 | Modified: Apr 09, 2025
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
6.9 MEDIUM
AV:L/AC:M/Au:N/C:C/I:C/A:C
RedHat/V2
5.4 LOW
AV:L/AC:M/Au:N/C:N/I:P/A:C
RedHat/V3
Ubuntu
LOW
root.io logo minimus.io logo echo.ai logo

Red Hat Cluster Project 2.x allows local users to modify or overwrite arbitrary files via symlink attacks on files in /tmp, involving unspecified components in Resource Group Manager (aka rgmanager) before 2.03.09-1, gfs2-utils before 2.03.09-1, and CMAN - The Cluster Manager before 2.03.09-1 on Fedora 9.

Weakness

The product attempts to access a file based on the filename, but it does not properly prevent that filename from identifying a link or shortcut that resolves to an unintended resource.

Affected Software

NameVendorStart VersionEnd Version
Cluster_projectRedhat2.00.00 (including)2.00.00 (including)
Cluster_projectRedhat2.01.00 (including)2.01.00 (including)
Cluster_projectRedhat2.02.00 (including)2.02.00 (including)
Cluster_projectRedhat2.03.00 (including)2.03.00 (including)
Cluster_projectRedhat2.03.01 (including)2.03.01 (including)
Cluster_projectRedhat2.03.03 (including)2.03.03 (including)
Cluster_projectRedhat2.03.04 (including)2.03.04 (including)
Cluster_projectRedhat2.03.05 (including)2.03.05 (including)
Cluster_projectRedhat2.03.7 (including)2.03.7 (including)
Cluster_projectRedhat2.03.08 (including)2.03.08 (including)
Cluster_projectRedhat2.03.09 (including)2.03.09 (including)
Cluster_projectRedhat2.03.10 (including)2.03.10 (including)
Cluster_projectRedhat2.03.11 (including)2.03.11 (including)
Cluster_projectRedhat2.99.00 (including)2.99.00 (including)
Cluster_projectRedhat2.99.01 (including)2.99.01 (including)
Cluster_projectRedhat2.99.02 (including)2.99.02 (including)
Cluster_projectRedhat2.99.03 (including)2.99.03 (including)
Cluster_projectRedhat2.99.04 (including)2.99.04 (including)
Cluster_projectRedhat2.99.05 (including)2.99.05 (including)
Cluster_projectRedhat2.99.06 (including)2.99.06 (including)
Cluster_projectRedhat2.99.07 (including)2.99.07 (including)
Cluster_projectRedhat2.99.08 (including)2.99.08 (including)
Cluster_projectRedhat2.99.09 (including)2.99.09 (including)
Cluster_projectRedhat2.99.10 (including)2.99.10 (including)
Cluster_projectRedhat2.99.11 (including)2.99.11 (including)
Cluster_projectRedhat2.99.12 (including)2.99.12 (including)
Cluster_projectRedhat2.99.13 (including)2.99.13 (including)
CLuster Suite for RHEL 4RedHatrgmanager-0:1.9.88-2.el4*
CLuster Suite for RHEL 4RedHatccs-0:1.0.13-2*
Red Hat Enterprise Linux 5RedHatrgmanager-0:2.0.52-1.el5*
Red Hat Enterprise Linux 5RedHatgfs2-utils-0:0.1.62-1.el5*
Red Hat Enterprise Linux 5RedHatcman-0:2.0.115-1.el5*
Redhat-clusterUbuntuhardy*
Redhat-clusterUbuntuintrepid*
Redhat-cluster-suiteUbuntudapper*
Redhat-cluster-suiteUbuntugutsy*

Potential Mitigations

  • Follow the principle of least privilege when assigning access rights to entities in a software system.
  • Denying access to a file can prevent an attacker from replacing that file with a link to a sensitive file. Ensure good compartmentalization in the system to provide protected areas that can be trusted.

References