LWN.net Logo

minitube: insecure tmp file handling

Package(s):minitube CVE #(s):
Created:March 16, 2012 Updated:March 21, 2012
Description:

From the Gentoo advisory:

Tomáš Pružina reported that Minitube does not handle temporary files securely.

A local attacker could perform symlink attacks to overwrite arbitrary files with the privileges of the user running the application.

Alerts:
Gentoo 201203-18 2012-03-16

(Log in to post comments)

Copyright © 2013, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds