LWN.net Logo

feta: insecure temp file handling

Package(s):feta CVE #(s):CVE-2008-4440
Created:October 7, 2008 Updated:October 8, 2008
Description: From the Debian advisory:

Dmitry E. Oboukhov discovered that the "to-upgrade" plugin of Feta, a simpler interface to APT, dpkg, and other Debian package tools creates temporary files insecurely, which may lead to local denial of service through symlink attacks.

Alerts:
Debian DSA-1643-1 2008-10-05

(Log in to post comments)

Copyright © 2013, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds