LWN.net Logo

inkscape: insecure temp files

Package(s):inkscape CVE #(s):CVE-2005-3885
Created:December 5, 2005 Updated:December 7, 2005
Description: Javier Fernández-Sanguino Peña discovered that Inkscape's ps2epsi.sh script, which converts PostScript files to Encapsulated PostScript format, creates a temporary file in an insecure way. A local attacker could exploit this with a symlink attack to create or overwrite arbitrary files with the privileges of the user running Inkscape.
Alerts:
Ubuntu USN-223-1 2005-12-05

(Log in to post comments)

inkscape: insecure temp files

Posted Dec 8, 2005 19:36 UTC (Thu) by kreutzm (guest, #4700) [Link]

This is closed in Debian as well, see DSA 916

Copyright © 2013, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds