LWN.net Logo

lha: temporary file vulnerability

Package(s):lha CVE #(s):CVE-2007-2030
Created:June 6, 2007 Updated:June 6, 2007
Description: The lha utility creates temporary files in an insecure manner, enabling symlink race attacks.
Alerts:
Mandriva MDKSA-2007:117 2007-06-05

(Log in to post comments)

lha: temporary file vulnerability

Posted Jun 8, 2007 19:50 UTC (Fri) by roelofs (guest, #2599) [Link]

Fedora update got appended to an old gzip bug for some reason:

http://lwn.net/Articles/200056/

Greg

Copyright © 2013, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds