CVE-2008-5153: Improper Link Resolution Before File Access ('Link Following')
(updated )
spell-check-logic.cgi in Moodle 1.8.2 allows local users to overwrite arbitrary files via a symlink attack on the (1) /tmp/spell-check-debug.log, (2) /tmp/spell-check-before, or (3) /tmp/spell-check-after temporary file.
References
- lists.debian.org/debian-devel/2008/08/msg00347.html
- www.debian.org/security/2009/dsa-1724
- exchange.xforce.ibmcloud.com/vulnerabilities/46708
- github.com/advisories/GHSA-x7r4-26m9-hmgq
- nvd.nist.gov/vuln/detail/CVE-2008-5153
- web.archive.org/web/20090821033319/http://secunia.com/advisories/33955
- web.archive.org/web/20110511083352/http://uvw.ru/report.sid.txt
- web.archive.org/web/20141121115305/http://www.securityfocus.com/bid/32402
Detect and mitigate CVE-2008-5153 with GitLab Dependency Scanning
Secure your software supply chain by verifying that all open source dependencies used in your projects contain no disclosed vulnerabilities. Learn more about Dependency Scanning →