Unrated severityNVD Advisory· Published Oct 7, 2008· Updated Apr 23, 2026
CVE-2008-4474
CVE-2008-4474
Description
freeradius-dialupadmin in freeradius 2.0.4 allows local users to overwrite arbitrary files via a symlink attack on temporary files in (1) backup_radacct, (2) clean_radacct, (3) monthly_tot_stats, (4) tot_stats, and (5) truncate_radacct.
Affected products
1- cpe:2.3:a:freeradius:freeradius:2.0.4:*:*:*:*:*:*:*
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
10- bugs.debian.org/cgi-bin/bugreport.cginvd
- dev.gentoo.org/~rbu/security/debiantemp/freeradius-dialupadminnvd
- lists.debian.org/debian-devel/2008/08/msg00271.htmlnvd
- lists.opensuse.org/opensuse-security-announce/2008-12/msg00003.htmlnvd
- secunia.com/advisories/32170nvd
- secunia.com/advisories/33151nvd
- uvw.ru/report.lenny.txtnvd
- www.openwall.com/lists/oss-security/2008/10/30/2nvd
- www.securityfocus.com/bid/30901nvd
- bugs.gentoo.org/show_bug.cginvd
News mentions
0No linked articles in our index yet.