LWN.net Logo

muttprint: insecure temporary files

Package(s):muttprint CVE #(s):CVE-2008-5368
Created:March 24, 2009 Updated:March 25, 2009
Description: From the Gentoo advisory: Dmitry E. Oboukhov reported an insecure usage of the temporary file "/tmp/muttprint.log" in the muttprint script. A local attacker could perform symlink attacks to overwrite arbitrary files with the privileges of the user running the application.
Alerts:
Gentoo 200903-35 2009-03-23

(Log in to post comments)

Copyright © 2013, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds