{"id":"CVE-2008-4953","details":"firehol in firehol 1.256 allows local users to overwrite arbitrary files via a symlink attack on (1) /tmp/.firehol-tmp-#####-*-* and (2) /tmp/firehol.conf temporary files.  NOTE: the vendor disputes this vulnerability, stating that an attack \"would require an attacker to create 1073741824*PID-RANGE symlinks.","modified":"2026-04-10T03:40:14.724517Z","published":"2008-11-05T15:00:15Z","database_specific":{"isDisputed":true},"references":[{"type":"WEB","url":"http://bugs.debian.org/496424"},{"type":"WEB","url":"http://dev.gentoo.org/~rbu/security/debiantemp/firehol"},{"type":"WEB","url":"http://www.openwall.com/lists/oss-security/2008/10/30/2"},{"type":"WEB","url":"https://bugs.gentoo.org/show_bug.cgi?id=235770"}],"schema_version":"1.7.5"}