|
|
| |
|
| |
skktools: insecure temporary file creation
| Package(s): | skktools |
CVE #(s): | CVE-2007-3916
|
| Created: | October 15, 2007 |
Updated: | October 17, 2007 |
| Description: |
skkdic-expr.c insecurely writes temporary files to a location in the form
$TMPDIR/skkdic$PID.{pag,dir,db}, where $PID is the process ID. A local
attacker could create symbolic links in the directory where the temporary
files are written, pointing to a valid file somewhere on the filesystem
that is writable by the user running the SKK software. When SKK writes the
temporary file, the target valid file would then be overwritten with the
contents of the SKK temporary file. |
| Alerts: |
|
( Log in to post comments)
|
|
|