CVE-2008-0884 describes a privilege escalation vulnerability affecting Red Hat Enterprise Linux 5. The flaw exists in the capp-lspp-config script, specifically in the lspp-eal4-config-ibm and capp-lspp-eal4-config-hp packages, where an incorrect use of lstat instead of stat leads to the /etc/pam.d/system-auth-ac file becoming world-writable. This misconfiguration allows local users to modify the file and subsequently gain elevated privileges. The vulnerability carries a CVSS score of 6.9, indicating high severity with a local attack vector and medium attack complexity, resulting in complete compromise of confidentiality, integrity, and availability. Its FAUCET Risk Score is 40/100. Despite its severity, there is no evidence of active exploitation, and no public exploit code is available in Metasploit, Nuclei, or ExploitDB. The vulnerability has received minimal community discussion and media coverage, suggesting a low profile in the threat landscape.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
5.0CPE matchmatch criteria | cpe:2.3:o:redhat:enterprise_linux:5.0:*:*:*:*:*:*:* |
CVSS version used by this source: 2.0
AV:L/AC:M/Au:N/C:C/I:C/A:C
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.