LWN.net Logo

m4: execution of arbitrary code

Package(s):m4 CVE #(s):CVE-2008-1687 CVE-2008-1688
Created:April 8, 2008 Updated:April 9, 2008
Description: m4-1.4.11 fixes two issues with possible security implications. A minor security fix with the use of "maketemp" and "mkstemp" -- these are now quoted to prevent the (rather unlikely) possibility that an unquoted string could match an existing macro causing operations to be done on the wrong file. Also, a problem with the '-F' option (introduced with version 1.4) could cause a core dump or possibly (with certain file names) the execution of arbitrary code.
Alerts:
Slackware SSA:2008-098-01 2008-04-08

(Log in to post comments)

Copyright © 2008, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds
Powered by Rackspace Managed Hosting.