|
|
| |
|
| |
cman: insecure temp file
| Package(s): | cman |
CVE #(s): | CVE-2008-4192
|
| Created: | October 23, 2008 |
Updated: | February 16, 2011 |
| Description: |
cman has an insecure temp file vulnerability. From the Red Hat
bug report:
A malicious user could precreate a symlink, pointing to the file /tmp/eglog,
Subsequent run of the '/sbin/egenera' command would destroy / truncate the
target of this link to zero length.
|
| Alerts: |
|
( Log in to post comments)
|
|
|