|
|
| |
|
| |
openswan: insecure tmp file usage
| Package(s): | openswan |
CVE #(s): | CVE-2008-4190
|
| Created: | March 9, 2009 |
Updated: | April 9, 2009 |
| Description: |
From the Gentoo advisory:
Dmitry E. Oboukhov reported that the IPSEC livetest tool does not
handle the ipseclive.conn and ipsec.olts.remote.log temporary files
securely.
A local attacker could perform symlink attacks to execute arbitrary
code and overwrite arbitrary files with the privileges of the user
running the application.
|
| Alerts: |
|
( Log in to post comments)
|
|
|