CVE-2008-0167 describes a vulnerability in the write_array_file function of GForge 4.5.14, where configuration files are truncated before new data is written, potentially allowing attackers to bypass access restrictions. This vulnerability affects GForge and Debian Linux distributions. With a CVSS score of 4.6, it is considered a low-severity local vulnerability (AV:L/AC:L/Au:N/C:P/I:P/A:P), meaning an attacker needs local access to exploit it, leading to potential partial confidentiality, integrity, and availability impacts. There is no evidence of active exploitation, no known Metasploit or Nuclei modules, and only one ExploitDB entry (EDB-5173) which is for a different product. Community discussion and media coverage are minimal, indicating low public attention.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
4.5.14CPE matchmatch criteria | cpe:2.3:a:gforge:gforge:4.5.14:*:*:*:*:*:*:* |
CVSS version used by this source: 2.0
AV:L/AC:L/Au:N/C:P/I:P/A:P
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.