The write_array_file function in utils/include.pl in GForge 4.5.14 updates configuration...
Vulnerability Description
The write_array_file function in utils/include.pl in GForge 4.5.14 updates configuration files by truncating them to zero length and then writing new data, which might allow attackers to bypass intended access restrictions or have unspecified other impact in opportunistic circumstances.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2008-0167
Credits & Attribution
No credits recorded in the NVD database.
References
- http://www.securityfocus.com/bid/29215
- http://secunia.com/advisories/30286
- http://security.debian.org/pool/updates/main/g/gforge/gforge_4.5.14-22etch8.diff.gz
- http://www.vupen.com/english/advisories/2008/1537/references
- http://secunia.com/advisories/30088
- http://www.debian.org/security/2008/dsa-1577
- https://exchange.xforce.ibmcloud.com/vulnerabilities/42456
More from gforge
View All →Affected Vendor
gforge
View all reports →Affected Software
Timeline
CVSS Vectors
Weaknesses (CWE)
No CWE data available
MITRE ATT&CK TTPs
No associated TTPs found for this vulnerability.