{"id":"DEBIAN-CVE-2008-4108","details":"Tools/faqwiz/move-faqwiz.sh (aka the generic FAQ wizard moving tool) in Python 2.4.5 might allow local users to overwrite arbitrary files via a symlink attack on a tmp$RANDOM.tmp temporary file.  NOTE: there may not be common usage scenarios in which tmp$RANDOM.tmp is located in an untrusted directory.","modified":"2026-08-04T06:03:19.807641442Z","published":"2008-09-18T17:59:33.093Z","upstream":["CVE-2008-4108"],"references":[{"type":"ADVISORY","url":"https://security-tracker.debian.org/tracker/CVE-2008-4108"}],"affected":[{"package":{"name":"python-defaults","ecosystem":"Debian:11","purl":"pkg:deb/debian/python-defaults?arch=source&distro=bullseye"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"}]}],"versions":["2.7.18-3"],"ecosystem_specific":{"urgency":"unimportant"},"database_specific":{"source":"https://storage.googleapis.com/debian-osv/debian-cve-osv/DEBIAN-CVE-2008-4108.json"}}],"schema_version":"1.8.0"}