{"id":"DEBIAN-CVE-2008-5135","details":"os-prober in os-prober 1.17 allows local users to overwrite arbitrary files via a symlink attack on the (1) /tmp/mounted-map or (2) /tmp/raided-map temporary file.  NOTE: the vendor disputes this issue, stating \"the insecure code path should only ever run inside a d-i environment, which has no non-root users.","modified":"2026-09-20T06:47:31.775465576Z","published":"2008-11-18T16:00:01Z","upstream":["CVE-2008-5135"],"references":[{"type":"ADVISORY","url":"https://security-tracker.debian.org/tracker/CVE-2008-5135"}],"affected":[{"package":{"name":"os-prober","ecosystem":"Debian:12","purl":"pkg:deb/debian/os-prober?arch=source&distro=bookworm"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"}]}],"versions":["1.81","1.82","1.83","1.84","1.85"],"ecosystem_specific":{"urgency":"unimportant"},"database_specific":{"source":"https://storage.googleapis.com/debian-osv/debian-cve-osv/DEBIAN-CVE-2008-5135.json"}},{"package":{"name":"os-prober","ecosystem":"Debian:13","purl":"pkg:deb/debian/os-prober?arch=source&distro=trixie"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"}]}],"versions":["1.83","1.84","1.85"],"ecosystem_specific":{"urgency":"unimportant"},"database_specific":{"source":"https://storage.googleapis.com/debian-osv/debian-cve-osv/DEBIAN-CVE-2008-5135.json"}},{"package":{"name":"os-prober","ecosystem":"Debian:14","purl":"pkg:deb/debian/os-prober?arch=source&distro=forky"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"}]}],"versions":["1.83","1.84","1.85"],"ecosystem_specific":{"urgency":"unimportant"},"database_specific":{"source":"https://storage.googleapis.com/debian-osv/debian-cve-osv/DEBIAN-CVE-2008-5135.json"}}],"schema_version":"1.9.0"}