|
|
| |
|
| |
FireHOL: insecure temporary file creation
| Package(s): | FireHOL |
CVE #(s): | |
| Created: | February 1, 2005 |
Updated: | February 1, 2005 |
| Description: |
FireHOL insecurely creates temporary files with predictable names. A local
attacker could create malicious symbolic links to arbitrary system
files. When FireHOL is executed, this could lead to these files being
overwritten with the rights of the user launching FireHOL, usually the root
user. |
| Alerts: |
|
( Log in to post comments)
|
|
|