LWN.net Logo

chm2pdf: two insecure tmp file flaws

Package(s):chm2pdf CVE #(s):CVE-2008-5298 CVE-2008-5299
Created:January 28, 2011 Updated:February 2, 2011
Description:

From the Red Hat bugzilla entries [1, 2]:

chm2pdf 0.9 uses temporary files in directories with fixed names, which allows local users to cause a denial of service (chm2pdf failure) of other users by creating those directories ahead of time. (CVE-2008-5298)

chm2pdf 0.9 allows user-assisted local users to delete arbitrary files via a symlink attack on .chm files in the (1) /tmp/chm2pdf/work or (2) /tmp/chm2pdf/orig temporary directories. (CVE-2008-5299)

Alerts:
Fedora FEDORA-2011-0454 2011-01-17
Fedora FEDORA-2011-0467 2011-01-17

(Log in to post comments)

Copyright © 2013, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds