CVE-2008-5380

gpsdrive 2.09 - Local Privilege Escalation

Title source: llm
STIX 2.1

Description

gpsdrive (aka gpsdrive-scripts) 2.09 allows local users to overwrite arbitrary files via a symlink attack on an (a) /tmp/geo#####, a (b) /tmp/geocaching.loc, a (c) /tmp/geo#####.*, or a (d) /tmp/geo.* temporary file, related to the (1) geo-code and (2) geo-nearest scripts, different vectors than CVE-2008-4959.

References (4)

Core 4
Core References
Third Party Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/31694
Third Party Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/33825
Mailing List mailing-list x_refsource_mlist
http://lists.debian.org/debian-devel/2008/08/msg00285.html

Scores

EPSS 0.0030
EPSS Percentile 21.2%

Details

CWE
CWE-59
Status published
Products (1)
gpsdrive/gpsdrive 2.09
Published Dec 08, 2008
Tracked Since Feb 18, 2026