Title : Debian Security Update Fixes Feta Temporary File Vulnerability VUPEN ID : VUPEN/ADV-2008-2733 CVE ID : CVE-2008-4440
Rated as : Low Risk
Remotely Exploitable : No Locally Exploitable : Yes Release Date : 2008-10-06
Technical Description
A vulnerability has been identified in Debian, which could be exploited by local attackers to bypass security restrictions. This issue is caused by an error in the "to-upgrade" plugin of Feta when handling temporary files, which could allow malicious users to conduct symlink attacks and cause a denial of service.