CVE-2008-5380 Information

Description

gpsdrive (aka gpsdrive-scripts) 2.09 allows local users to overwrite arbitrary files via a symlink attack on an (a) /tmp/geo a (b) /tmp/geocaching.loc a (c) /tmp/geo.* or a (d) /tmp/geo.* temporary file related to the (1) geo-code and (2) geo-nearest scripts different vectors than CVE-2008-4959.

Reference

http://lists.debian.org/debian-devel/2008/08/msg00285.html http://secunia.com/advisories/31694 http://secunia.com/advisories/33825 https://www.redhat.com/archives/fedora-package-announce/2009-February/msg00187.html

Share on: