View at Official ubuntu advisory, NVD, CVE.org · CVE detail
Freshness: upstream tracker timestamp is available; use API updated time as primary recency signal.
CVE-2008-4192 low priority: Ubuntu including 2 source packages (redhat-cluster, redhat-cluster-suite), 16 status rows across 8 suites (dapper, feisty, gutsy, hardy, intrepid, jaunty, karmic, upstream): DNE 7, not-affected 6, released 2, needs-triage 1.
The pserver_shutdown function in fence_egenera in cman 2.20080629 and 2.20080801 allows local users to overwrite arbitrary files via a symlink attack on the /tmp/eglog temporary file.