|
|
| |
|
| |
ed: Insecure temporary file handling
| Package(s): | ed |
CVE #(s): | CVE-2000-1137
|
| Created: | October 11, 2004 |
Updated: | October 13, 2004 |
| Description: |
ed insecurely creates temporary files in world-writeable directories with
predictable names. Given that ed is used in various system shell scripts,
they are by extension affected by the same vulnerability. A local attacker
could create symbolic links in the temporary files directory, pointing to a
valid file somewhere on the filesystem. When ed is called, this would
result in file access with the rights of the user running the utility,
which could be the root user. |
| Alerts: |
|
( Log in to post comments)
|
|
|