CVE detail
CVE-2008-0884 — CVE-2008-0884
Published 2008-04-04 · Modified 2026-06-16 · Vendor redhat · Product enterprise_linux · Source nvd
UNKNOWN
severity
CVSS-derived band
0.0036
EPSS probability
exploitation probability, 30d
29.0%
EPSS percentile
percentile vs all CVEs
NOT LISTED
CISA KEV
known exploited catalog
Description
The Replace function in the capp-lspp-config script in the (1) lspp-eal4-config-ibm and (2) capp-lspp-eal4-config-hp packages before 0.65-2 in Red Hat Enterprise Linux (RHEL) 5 uses lstat instead of stat to determine the /etc/pam.d/system-auth file permissions, leading to a change to world-writable permissions for the /etc/pam.d/system-auth-ac file, which allows local users to gain privileges by modifying this file.
Remediation
No vendor-published fix data in our corpus for this CVE. Check the references below or the vendor's PSIRT / security advisories page.
References