{"id":"ECHO-9fa2-4bcd-f5ba","upstream":["CVE-2008-4950"],"severity":[],"modified":"2026-01-08T16:00:16.570Z","affected":[{"package":{"ecosystem":"Echo","name":"dpkg-cross"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"2.6.20"}]}]}],"references":[{"type":"WEB","url":"https://advisory.echohq.com/cve/CVE-2008-4950"},{"type":"WEB","url":"https://nvd.nist.gov/vuln/detail/CVE-2008-4950"},{"type":"WEB","url":"http://bugs.debian.org/496413"},{"type":"WEB","url":"http://dev.gentoo.org/~rbu/security/debiantemp/dpkg-cross"},{"type":"WEB","url":"http://www.openwall.com/lists/oss-security/2008/10/30/2"},{"type":"WEB","url":"https://bugs.gentoo.org/show_bug.cgi?id=235770"},{"type":"WEB","url":"http://bugs.debian.org/496413"},{"type":"WEB","url":"http://dev.gentoo.org/~rbu/security/debiantemp/dpkg-cross"},{"type":"WEB","url":"http://www.openwall.com/lists/oss-security/2008/10/30/2"},{"type":"WEB","url":"https://bugs.gentoo.org/show_bug.cgi?id=235770"}],"withdrawn":"2026-01-08T16:00:16.570Z","summary":"gccross in dpkg-cross 2.3.0 allows local users to overwrite arbitrary files\nvia a symlink attack on the tmp/gccross2.log temporary file.\nThe vendor disputes this vulnerability, stating that \"There is no sense in this bug - the script is installed in /usr/share/\nand is called under specific cross-building environments within a chroot\".\n"}