CVE-2008-2266
EPSS 0.32%
Description
uulib/uunconc.c in UUDeview 0.5.20, as used in nzbget before 0.3.0 and possibly other products, allows local users to overwrite arbitrary files via a symlink attack on a temporary filename generated by the tempnam function. NOTE: this may be a CVE-2004-2265 regression.
How to fix CVE-2008-2266
To remediate CVE-2008-2266, upgrade the affected package to a fixed version below.
- Debian/uudeview—upgrade to 0.5.20-3.1 or later
Is CVE-2008-2266 being exploited?
Low — EPSS is 0.3%, meaning exploitation activity has not been observed at scale.
Affected packages (1)
- from 0, < 0.5.20-3.1