CVE-2007-4998 describes a local symlink attack vulnerability in the 'cp' utility, affecting Linux kernel and other Linux distributions, when preserving symlinks. An attacker can overwrite arbitrary files by crafting directories with multiple source files targeting the same destination. This vulnerability carries a CVSS score of 6.9, indicating high severity due to its local attack vector, medium attack complexity, and complete confidentiality, integrity, and availability impacts. There is no known active exploitation, public exploit code (Metasploit, Nuclei, ExploitDB), or significant community discussion or media coverage surrounding this CVE.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
All Versions ImpactedCPE matchmatch criteria | cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* |
CVSS version used by this source: 2.0
AV:L/AC:M/Au:N/C:C/I:C/A:C
No social media mentions found for this CVE.
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
CVE-2007-4998
Sep 8, 2020cp symlink overwrite
Jan 22, 2008cp when running with an option to preserve symlinks on multiple OSes allows local user-assisted attackers to overwrite arbitrary files via a symlink attack using crafted directories containing multiple source files that are copied to the same destination.
Jan 2, 2008