Checkinstall is a Linux package-creation utility that automates the conversion of source distributions into native system packages, with its vulnerability profile centered on a single tool and characterized by race-condition weaknesses in file handling and resource synchronization. The observed exposure reflects the tool's role in privileged package operations where concurrent file access and improper locking can create window-of-opportunity flaws. Current severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Checkinstall over time
Signals from CVEs in this vendor scope (1 CVEs).
1 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2008-2958MEDIUM Race condition in (1) checkinstall 1.6.1 and (2) installwatch allows local users to overwrite arbitrary files and have other impacts via symlink and possibly other attacks on tempo | Jul 1, 2008 | 4.4 | 14 | NO | NO |
Signals from CVEs in this vendor scope (1 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Checkinstall.
Media articles that mention a CVE ID that affects a product developed by Checkinstall — matched by CVE ID, not by vendor name.