|
|
| |
|
| |
sharutils: insecure temporary files
| Package(s): | sharutils |
CVE #(s): | |
| Created: | April 4, 2005 |
Updated: | April 14, 2005 |
| Description: |
Joey Hess discovered that "unshar" created temporary files in an
insecure manner. This could allow a symbolic link attack to create or
overwrite arbitrary files with the privileges of the user invoking the
program. |
| Alerts: |
|
( Log in to post comments)
|
|
|