LWN.net Logo

fwbuilder: symlink attack

Package(s):fwbuilder CVE #(s):
Created:February 16, 2010 Updated:February 17, 2010
Description: From the Red Hat bugzilla:

An insecure temporary file handling in the generated iptables script was found in fwbuilder. A local attacker could use this flaw to perform symlink attack against user running this script, which will result in overwrite of arbitrary file writable by this script.

Alerts:
Fedora FEDORA-2010-0157 2010-01-05
Fedora FEDORA-2010-0157 2010-01-05

(Log in to post comments)

Copyright © 2013, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds