Description
rc.sysinit in initscripts before 8.76.3-1 on Fedora 9 and other Linux platforms allows local users to delete arbitrary files via a symlink attack on a file or directory under (1) /var/lock or (2) /var/run.
Affected products
- RedHat / fedora9 – 9
- RedHat / initscripts8.76.3 – 8.76.3
References
- MISChttp://www.securityfocus.com/bid/31385
- MISChttps://www.redhat.com/archives/fedora-package-announce/2008-September/msg01135.html
- MISChttps://bugzilla.redhat.com/show_bug.cgi?id=458504
- MISChttps://bugzilla.redhat.com/show_bug.cgi?id=458652
- MISChttps://exchange.xforce.ibmcloud.com/vulnerabilities/45402
- VENDOR_ADVISORYhttp://secunia.com/advisories/32710
- VENDOR_ADVISORYhttp://secunia.com/advisories/32037
- MISChttps://issues.rpath.com/browse/RPL-2857
- VENDOR_ADVISORYhttp://wiki.rpath.com/wiki/Advisories:rPSA-2008-0318