|
|
| |
|
| |
inkscape: insecure temp files
| Package(s): | inkscape |
CVE #(s): | CVE-2005-3885
|
| Created: | December 5, 2005 |
Updated: | December 7, 2005 |
| Description: |
Javier Fernández-Sanguino Peña discovered that Inkscape's ps2epsi.sh
script, which converts PostScript files to Encapsulated PostScript
format, creates a temporary file in an insecure way. A local attacker
could exploit this with a symlink attack to create or overwrite
arbitrary files with the privileges of the user running Inkscape. |
| Alerts: |
|
( Log in to post comments)
|
|
|