LWN.net Logo

openswan: insecure tmp file usage

Package(s):openswan CVE #(s):CVE-2008-4190
Created:March 9, 2009 Updated:April 9, 2009
Description:

From the Gentoo advisory:

Dmitry E. Oboukhov reported that the IPSEC livetest tool does not handle the ipseclive.conn and ipsec.olts.remote.log temporary files securely.

A local attacker could perform symlink attacks to execute arbitrary code and overwrite arbitrary files with the privileges of the user running the application.

Alerts:
CentOS CESA-2009:0402 2009-04-09
Debian DSA-1760-1 2009-03-30
Red Hat RHSA-2009:0402-01 2009-03-30
Gentoo 200903-18 2009-03-09

(Log in to post comments)

Copyright © 2013, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds