LWN.net Logo

rocksndiamonds: arbitrary file overwrite

Package(s):rocksndiamonds CVE #(s):CVE-2011-4606
Created:February 21, 2012 Updated:August 3, 2012
Description: From the CVE entry:

Artsoft Entertainment Rocks'n'Diamonds (aka rocksndiamonds) 3.3.0.1 allows local users to overwrite arbitrary files via a symlink attack on .rocksndiamonds/cache/artworkinfo.cache under a user's home directory.

Alerts:
Fedora FEDORA-2012-1567 2012-02-21
openSUSE openSUSE-SU-2012:0918-1 2012-07-27
Mageia MGASA-2012-0195 2012-08-02

(Log in to post comments)

Copyright © 2013, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds