LWN.net Logo

mgetty: insecure use of tmp file

Package(s):mgetty CVE #(s):CVE-2008-4936
Created:December 8, 2008 Updated:December 10, 2008
Description:

From the Gentoo advisory:

Dmitry E. Oboukhov reported that the "spooldir" directory in fax/faxspool.in is created in an insecure manner.

A local attacker could exploit this vulnerability to overwrite arbitrary files with the privileges of the user running the application.

Alerts:
Gentoo 200812-08 2008-12-06

(Log in to post comments)

Copyright © 2013, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds