CVE-2008-1570
Dashboard / Vulnerabilities / CVE-2008-1570
CVE-2008-1570
Published: 31 Mar 2008Last Modified: 10 Apr 2026
Summary:
Details: Race condition in the create_lockpath function in policyd-weight 0.1.14 beta-16 allows local users to modify or delete arbitrary files by creating the LOCKPATH directory, then modifying it after the symbolic link check occurs. NOTE: this is due to an incomplete fix for CVE-2008-1569.
References: http://secunia.com/advisories/29738, http://security.gentoo.org/glsa/glsa-200804-11.xml, http://www.osvdb.org/43888, https://bugs.gentoo.org/show_bug.cgi?id=214403, https://exchange.xforce.ibmcloud.com/vulnerabilities/41570
Affected packages
Common Vulnerability Scoring System
Attack Vector
Network
Adjacent
Local
Physical
Privileges Required
None
Low
High
User Interaction
None
Required
Scope
Unchanged
Changed
Confidentiality
None
Low
High
Integrity
None
Low
High
Availability
None
Low
High
