CVE-2008-4996

Publication date 7 November 2008

Last updated 4 August 2025


Ubuntu priority

Negligible

Why this priority?

Cvss 3 Severity Score

5.5 · Medium

Score breakdown

Description

init in initramfs-tools 0.92f allows local users to overwrite arbitrary files via a symlink attack on the /tmp/initramfs.debug temporary file. NOTE: the vendor disputes this vulnerability, stating that "init is [used in] a single-user context; there's no possibility that this is exploitable.

Read the notes from the security team

Status

Package Ubuntu Release Status
initramfs-tools 9.10 karmic Ignored
9.04 jaunty Ignored
8.10 intrepid Ignored
8.04 LTS hardy Ignored
7.10 gutsy Ignored end of life, was needed
6.06 LTS dapper Ignored

Notes


jdstrand

per upstream, occurs in init, which is a single-user context


mdeslaur

not exploitable, let's ignore

Severity score breakdown

CVSS version: CVSS v3.0

Base score 5.5 · Medium

Vector: CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N


Access our resources on patching vulnerabilities