LWN.net Logo

coreutils: symlink attacks

Package(s):coreutils CVE #(s):CVE-2009-4135
Created:December 18, 2009 Updated:January 25, 2010
Description: From the Red Hat bugzilla: The "distcheck" Makefile rule in coreutils 5.2.1 through to 8.1 did use unsafe (predictable) temporary directory location for performing own tasks. This might allow local attacker to conduct symlink attacks under certain circumstances.
Alerts:
Mandriva MDVSA-2010:024 2010-01-23
Fedora FEDORA-2009-13216 2009-12-16
Fedora FEDORA-2009-13181 2009-12-16

(Log in to post comments)

Copyright © 2012, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds