LWN.net Logo

bzip2: insecure tmp file creation

Package(s):bzip2 CVE #(s):CVE-2011-4089
Created:December 15, 2011 Updated:December 21, 2011
Description:

From the Ubuntu advisory:

vladz discovered that executables compressed by bzexe insecurely create temporary files when they are ran. A local attacker could exploit this issue to execute arbitrary code as the user running a compressed executable.

Alerts:
Ubuntu USN-1308-1 2011-12-14

(Log in to post comments)

Copyright © 2013, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds