|
| Package(s): | m4 |
CVE #(s): | CVE-2008-1687
CVE-2008-1688
|
| Created: | April 8, 2008 |
Updated: | April 9, 2008 |
| Description: |
m4-1.4.11 fixes two issues with possible security implications. A minor security fix with the use of "maketemp" and "mkstemp" -- these are now quoted to prevent the (rather unlikely) possibility that an unquoted string could match an existing macro causing operations to be done on the wrong file. Also, a problem with the '-F' option (introduced with version 1.4) could cause a core dump or possibly (with certain file names) the execution of arbitrary code. |
| Alerts: |
|
( Log in to post comments)
|