CVE-2008-0167
The write_array_file function in utils/include.pl in GForge 4.5.14 updates configuration files by truncating them to zero length and then writing new data, which might allow attackers to bypass intended access restrictions or have unspecified other…
Does this matter?
Lower severity and a low EPSS score (0.73%). Track it; it rarely justifies an emergency change on its own.
Description
The write_array_file function in utils/include.pl in GForge 4.5.14 updates configuration files by truncating them to zero length and then writing new data, which might allow attackers to bypass intended access restrictions or have unspecified other impact in opportunistic circumstances.
- CVSS 2.0
- 4.6 MEDIUMAV:L/AC:L/Au:N/C:P/I:P/A:P
- EPSS
- 0.73% probability · 52th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-59
- Affected
- gforge/gforge
- Source
- cve@mitre.org
References
- http://secunia.com/advisories/30088Vendor Advisory
- http://secunia.com/advisories/30286Vendor Advisory
- http://security.debian.org/pool/updates/main/g/gforge/gforge_4.5.14-22etch8.diff.gz
- http://www.debian.org/security/2008/dsa-1577Patch
- http://www.securityfocus.com/bid/29215
- http://www.vupen.com/english/advisories/2008/1537/references
- https://exchange.xforce.ibmcloud.com/vulnerabilities/42456
- http://secunia.com/advisories/30088Vendor Advisory
- http://secunia.com/advisories/30286Vendor Advisory
- http://security.debian.org/pool/updates/main/g/gforge/gforge_4.5.14-22etch8.diff.gz
- http://www.debian.org/security/2008/dsa-1577Patch
- http://www.securityfocus.com/bid/29215
- http://www.vupen.com/english/advisories/2008/1537/references
- https://exchange.xforce.ibmcloud.com/vulnerabilities/42456
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.