|
|
| |
|
| |
foomatic: insecure temporary files
| Package(s): | foomatic |
CVE #(s): | CVE-2011-2924
CVE-2011-2923
|
| Created: | September 26, 2011 |
Updated: | September 27, 2011 |
| Description: |
From the Red Hat bugzilla
It was found that foomatic-rip filter used insecurely created temporary file for storage of PostScript data by rendering the data, intended to be sent to the PostScript filter, when the debug mode was enabled. A local attacker could use this flaw to conduct symlink attacks (overwrite arbitrary file accessible with the privileges of the user running the foomatic-rip universal print filter).
|
| Alerts: |
|
( Log in to post comments)
|
|
|