LWN.net Logo

cman: insecure temp file

Package(s):cman CVE #(s):CVE-2008-4579
Created:October 23, 2008 Updated:February 16, 2011
Description: cman has an insecure temp file vulnerability. From the Red Hat bug report:

The fence_apc and fence_apc_snmp programs, as used in fence 2.02.00-r1 and possibly cman, when running in verbose mode, allows local users to append to arbitrary files via a symlink attack on the apclog temporary file.

Alerts:
Red Hat RHSA-2011:0266-01 2011-02-16
Gentoo 201009-09 2010-09-29
Ubuntu USN-875-1 2009-12-18
CentOS CESA-2009:1341 2009-09-15
Red Hat RHSA-2009:1341-02 2009-09-02
Fedora FEDORA-2008-9458 2008-11-07
Fedora FEDORA-2008-9458 2008-11-07
Fedora FEDORA-2008-9458 2008-11-07
Fedora FEDORA-2008-9042 2008-10-23

(Log in to post comments)

Copyright © 2013, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds