{"id":"DEBIAN-CVE-2008-4996","details":"init in initramfs-tools 0.92f allows local users to overwrite arbitrary files via a symlink attack on the /tmp/initramfs.debug temporary file.  NOTE: the vendor disputes this vulnerability, stating that \"init is [used in] a single-user context; there's no possibility that this is exploitable.","modified":"2026-09-20T07:00:54.185943754Z","published":"2008-11-07T19:36:23.963Z","upstream":["CVE-2008-4996"],"references":[{"type":"ADVISORY","url":"https://security-tracker.debian.org/tracker/CVE-2008-4996"}],"affected":[{"package":{"name":"initramfs-tools","ecosystem":"Debian:12","purl":"pkg:deb/debian/initramfs-tools?arch=source&distro=bookworm"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"}]}],"versions":["0.142","0.142+deb12u1","0.142+deb12u2","0.142+deb12u3","0.143","0.143.1","0.144","0.145","0.146","0.147","0.148","0.148.1","0.148.2","0.148.3","0.148.4","0.149","0.150","0.151"],"ecosystem_specific":{"urgency":"unimportant"},"database_specific":{"source":"https://storage.googleapis.com/debian-osv/debian-cve-osv/DEBIAN-CVE-2008-4996.json"}},{"package":{"name":"initramfs-tools","ecosystem":"Debian:13","purl":"pkg:deb/debian/initramfs-tools?arch=source&distro=trixie"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"}]}],"versions":["0.148.3","0.148.4","0.149","0.150","0.151"],"ecosystem_specific":{"urgency":"unimportant"},"database_specific":{"source":"https://storage.googleapis.com/debian-osv/debian-cve-osv/DEBIAN-CVE-2008-4996.json"}},{"package":{"name":"initramfs-tools","ecosystem":"Debian:14","purl":"pkg:deb/debian/initramfs-tools?arch=source&distro=forky"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"}]}],"versions":["0.148.3","0.148.4","0.149","0.150","0.151"],"ecosystem_specific":{"urgency":"unimportant"},"database_specific":{"source":"https://storage.googleapis.com/debian-osv/debian-cve-osv/DEBIAN-CVE-2008-4996.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N"}]}