LWN.net Logo

bournal: multiple vulnerabilities

Package(s):bournal CVE #(s):CVE-2010-0118 CVE-2010-0119
Created:March 9, 2010 Updated:March 10, 2010
Description: From the Red Hat bugzilla:

Bournal before 1.4.1 allows local users to overwrite arbitrary files via a symlink attack on unspecified temporary files associated with a --hack_the_gibson update check. CVE-2010-0118

Bournal before 1.4.1 on FreeBSD 8.0, when the -K option is used, places a ccrypt key on the command line, which allows local users to obtain sensitive information by listing the process and its arguments, related to "echoing." CVE-2010-0119

Alerts:
Fedora FEDORA-2010-3301 2010-03-02
Fedora FEDORA-2010-3221 2010-03-02
Fedora FEDORA-2010-3168 2010-03-01

(Log in to post comments)

Copyright © 2013, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds