DEBIAN-CVE-2008-4987

Source
https://security-tracker.debian.org/tracker/CVE-2008-4987
Import Source
https://storage.googleapis.com/osv-test-debian-osv/debian-cve-osv/DEBIAN-CVE-2008-4987.json
JSON Data
https://api.test.osv.dev/v1/vulns/DEBIAN-CVE-2008-4987
Upstream
Published
2008-11-06T15:55:52Z
Modified
2025-09-19T06:20:09Z
Summary
[none]
Details

xastir 1.9.2 allows local users to overwrite arbitrary files via a symlink attack on the (a) /tmp/ldconfig.tmp, (b) /tmp/ldconf.tmp, and (c) /tmp/ld.so.conf temporary files, related to the (1) get-maptools.sh and (2) get_shapelib.sh scripts.

References

Affected packages

Debian:11 / xastir

Package

Name
xastir
Purl
pkg:deb/debian/xastir?arch=source

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
1.9.2-1.1

Ecosystem specific

{
    "urgency": "low"
}

Debian:12 / xastir

Package

Name
xastir
Purl
pkg:deb/debian/xastir?arch=source

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
1.9.2-1.1

Ecosystem specific

{
    "urgency": "low"
}

Debian:13 / xastir

Package

Name
xastir
Purl
pkg:deb/debian/xastir?arch=source

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
1.9.2-1.1

Ecosystem specific

{
    "urgency": "low"
}

Debian:14 / xastir

Package

Name
xastir
Purl
pkg:deb/debian/xastir?arch=source

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
1.9.2-1.1

Ecosystem specific

{
    "urgency": "low"
}