CVE-2008-1078
Estado: ModificadaAlta (7.2)—
expn in the am-utils and net-fs packages for Gentoo, rPath Linux, and other distributions, allows local users to overwrite arbitrary files via a symlink attack on the expn[PID] temporary file. NOTE: this is the same issue as CVE-2003-0308.1.
CVSS
- Versión: 2.0
- Vector: AV:L/AC:L/Au:N/C:C/I:C/A:C
- Puntuación base: 7.2
Probabilidad de explotación (EPSS)
- Probabilidad de explotación en los próximos 30 días: 0.51%
- Percentil entre todas las CVEs puntuadas: 42
- Fecha de la puntuación: 6/10/2026
EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).
Tecnologías afectadas (2)
CWE
- CWE-59
Referencias
- http://bugs.gentoo.org/show_bug.cgi?id=210158
- http://secunia.com/advisories/29144
- http://secunia.com/advisories/29187
- http://secunia.com/advisories/29694
- http://secunia.com/advisories/33400
- http://wiki.rpath.com/wiki/Advisories:rPSA-2008-0088
- http://www.gentoo.org/security/en/glsa/glsa-200804-09.xml
- http://www.securityfocus.com/archive/1/488931/100/0/threaded
- http://www.securityfocus.com/bid/28044
- https://issues.rpath.com/browse/RPL-2255
- https://www.redhat.com/archives/fedora-package-announce/2009-January/msg00273.html
- http://bugs.gentoo.org/show_bug.cgi?id=210158
- http://secunia.com/advisories/29144
- http://secunia.com/advisories/29187
- http://secunia.com/advisories/29694
- http://secunia.com/advisories/33400
- http://wiki.rpath.com/wiki/Advisories:rPSA-2008-0088
- http://www.gentoo.org/security/en/glsa/glsa-200804-09.xml
- http://www.securityfocus.com/archive/1/488931/100/0/threaded
- http://www.securityfocus.com/bid/28044
- https://issues.rpath.com/browse/RPL-2255
- https://www.redhat.com/archives/fedora-package-announce/2009-January/msg00273.html
JSON original (NVD)
Mostrar
{
"id": "CVE-2008-1078",
"cveTags": [],
"metrics": {
"cvssMetricV2": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"cvssData": {
"version": "2.0",
"baseScore": 7.2,
"accessVector": "LOCAL",
"vectorString": "AV:L/AC:L/Au:N/C:C/I:C/A:C",
"authentication": "NONE",
"integrityImpact": "COMPLETE",
"accessComplexity": "LOW",
"availabilityImpact": "COMPLETE",
"confidentialityImpact": "COMPLETE"
},
"acInsufInfo": false,
"impactScore": 10,
"baseSeverity": "HIGH",
"obtainAllPrivilege": true,
"exploitabilityScore": 3.9,
"obtainUserPrivilege": false,
"obtainOtherPrivilege": false,
"userInteractionRequired": false
}
]
},
"affected": [
{
"source": "secalert@redhat.com",
"affectedData": [
{
"vendor": "n/a",
"product": "n/a",
"versions": [
{
"status": "affected",
"version": "n/a"
}
]
}
]
}
],
"published": "2008-02-29T02:44:00.000",
"references": [
{
"url": "http://bugs.gentoo.org/show_bug.cgi?id=210158",
"tags": [
"Exploit"
],
"source": "secalert@redhat.com"
},
{
"url": "http://secunia.com/advisories/29144",
"tags": [
"Vendor Advisory"
],
"source": "secalert@redhat.com"
},
{
"url": "http://secunia.com/advisories/29187",
"tags": [
"Vendor Advisory"
],
"source": "secalert@redhat.com"
},
{
"url": "http://secunia.com/advisories/29694",
"tags": [
"Vendor Advisory"
],
"source": "secalert@redhat.com"
},
{
"url": "http://secunia.com/advisories/33400",
"tags": [
"Vendor Advisory"
],
"source": "secalert@redhat.com"
},
{
"url": "http://wiki.rpath.com/wiki/Advisories:rPSA-2008-0088",
"source": "secalert@redhat.com"
},
{
"url": "http://www.gentoo.org/security/en/glsa/glsa-200804-09.xml",
"source": "secalert@redhat.com"
},
{
"url": "http://www.securityfocus.com/archive/1/488931/100/0/threaded",
"source": "secalert@redhat.com"
},
{
"url": "http://www.securityfocus.com/bid/28044",
"source": "secalert@redhat.com"
},
{
"url": "https://issues.rpath.com/browse/RPL-2255",
"source": "secalert@redhat.com"
},
{
"url": "https://www.redhat.com/archives/fedora-package-announce/2009-January/msg00273.html",
"source": "secalert@redhat.com"
},
{
"url": "http://bugs.gentoo.org/show_bug.cgi?id=210158",
"tags": [
"Exploit"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://secunia.com/advisories/29144",
"tags": [
"Vendor Advisory"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://secunia.com/advisories/29187",
"tags": [
"Vendor Advisory"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://secunia.com/advisories/29694",
"tags": [
"Vendor Advisory"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://secunia.com/advisories/33400",
"tags": [
"Vendor Advisory"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://wiki.rpath.com/wiki/Advisories:rPSA-2008-0088",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://www.gentoo.org/security/en/glsa/glsa-200804-09.xml",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://www.securityfocus.com/archive/1/488931/100/0/threaded",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://www.securityfocus.com/bid/28044",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "https://issues.rpath.com/browse/RPL-2255",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "https://www.redhat.com/archives/fedora-package-announce/2009-January/msg00273.html",
"source": "af854a3a-2127-422b-91ae-364da2661108"
}
],
"vulnStatus": "Modified",
"weaknesses": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"description": [
{
"lang": "en",
"value": "CWE-59"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "expn in the am-utils and net-fs packages for Gentoo, rPath Linux, and other distributions, allows local users to overwrite arbitrary files via a symlink attack on the expn[PID] temporary file. NOTE: this is the same issue as CVE-2003-0308.1."
},
{
"lang": "es",
"value": "expn en los paquetes am-utils y net-fs para Gentoo, rPath Linux y otras distribuciones, permite a usuarios locales sobrescribir archivos arbitrarios mediante un ataque de tipo symlink en el archivo temporal expn[PID]. NOTA: este es el mismo problema de CVE-2003-0308.1."
}
],
"lastModified": "2026-06-16T22:50:56.410",
"configurations": [
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:o:gentoo:linux:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "647BA336-5538-4972-9271-383A0EC9378E"
},
{
"criteria": "cpe:2.3:o:rpath:rpath_linux:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "745FEF27-20CE-4508-8373-421092A8C8A8"
}
],
"operator": "OR"
}
]
}
],
"vendorComments": [
{
"comment": "The risks associated with fixing this bug are greater than the low severity security risk.We therefore currently have no plans to fix this flaw in Red HatEnterprise Linux.\n\nFor more information please see the following bug:\nhttps://bugzilla.redhat.com/show_bug.cgi?id=435420",
"lastModified": "2008-03-04T00:00:00",
"organization": "Red Hat"
}
],
"sourceIdentifier": "secalert@redhat.com"
}