LWN.net Logo

sharutils: insecure temporary files

Package(s):sharutils CVE #(s):
Created:April 4, 2005 Updated:April 14, 2005
Description: Joey Hess discovered that "unshar" created temporary files in an insecure manner. This could allow a symbolic link attack to create or overwrite arbitrary files with the privileges of the user invoking the program.
Alerts:
Fedora FEDORA-2005-319 2005-04-14
Mandrake MDKSA-2005:067 2005-04-07
Gentoo 200504-06 2005-04-06
Ubuntu USN-104-1 2005-04-04

(Log in to post comments)

sharutils: insecure temporary files

Posted Apr 21, 2005 8:49 UTC (Thu) by mjc@redhat.com (guest, #2303) [Link]

This is CAN-2005-0990

http://cve.mitre.org/cgi-bin/cvename.cgi?name=CAN-2005-0990

Copyright © 2013, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds