CVE-2008-0525

PatchLink Update & Novell ZENworks Patch Management - Arbitrary File Truncation & Code Execution via Symlink Attacks

Title source: llm
STIX 2.1

Description

PatchLink Update client for Unix, as used by Novell ZENworks Patch Management Update Agent for Linux/Unix/Mac (LUM) 6.2094 through 6.4102 and other products, allows local users to (1) truncate arbitrary files via a symlink attack on the /tmp/patchlink.tmp file used by the logtrimmer script, and (2) execute arbitrary code via a symlink attack on the /tmp/plshutdown file used by the rebootTask script.

References (13)

Core 13
Core References
Third Party Advisory, VDB Entry vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/27458
Vendor Advisory vdb-entry x_refsource_vupen
http://www.vupen.com/english/advisories/2008/0426
Third Party Advisory third-party-advisory x_refsource_sreason
http://securityreason.com/securityalert/3599
Third Party Advisory, VDB Entry vdb-entry x_refsource_xf
https://exchange.xforce.ibmcloud.com/vulnerabilities/39958
Vendor Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/28657
Third Party Advisory, VDB Entry vdb-entry x_refsource_xf
https://exchange.xforce.ibmcloud.com/vulnerabilities/39956
Vendor Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/28665
Third Party Advisory, VDB Entry mailing-list x_refsource_bugtraq
http://www.securityfocus.com/archive/1/487103/100/0/threaded
Third Party Advisory, VDB Entry vdb-entry x_refsource_sectrack
http://www.securitytracker.com/id?1019272

Scores

EPSS 0.0011
EPSS Percentile 28.8%

Details

CWE
CWE-59
Status published
Products (6)
lumension_security/patchlink_update 6.2 (3 CPE variants)
lumension_security/patchlink_update 6.3 (3 CPE variants)
lumension_security/patchlink_update 6.4 (3 CPE variants)
novell/zenworks_patch_management_update_agent 6.2 (3 CPE variants)
novell/zenworks_patch_management_update_agent 6.3 (3 CPE variants)
novell/zenworks_patch_management_update_agent 6.4 (3 CPE variants)
Published Jan 31, 2008
Tracked Since Feb 18, 2026