CVE-2008-2958

checkinstall 1.6.1 - Arbitrary File Overwrite via Race Condition in Temporary Working Directory

Title source: llm
STIX 2.1

Description

Race condition in (1) checkinstall 1.6.1 and (2) installwatch allows local users to overwrite arbitrary files and have other impacts via symlink and possibly other attacks on temporary working directories.

References (4)

Core 4
Core References
Vendor Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/30873
Issue Tracking x_refsource_confirm
http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=488140
Third Party Advisory, VDB Entry vdb-entry x_refsource_xf
https://exchange.xforce.ibmcloud.com/vulnerabilities/43440

Scores

EPSS 0.0028
EPSS Percentile 20.0%

Details

CWE
CWE-362
Status published
Products (1)
checkinstall/checkinstall 1.6.1
Published Jul 01, 2008
Tracked Since Feb 18, 2026