|
|
| |
|
| |
python-suds: symbolic link attack
| Package(s): | python-suds |
CVE #(s): | CVE-2013-2217
|
| Created: | July 17, 2013 |
Updated: | July 22, 2013 |
| Description: |
From the bug report:
An insecure temporary directory use flaw was found in the way python-suds, a Python SOAP web services client library, performed initialization of its internal file-based URL cache (predictable location was used for directory to store the cached files). A local attacker could use this flaw to conduct symbolic link attacks, possibly leading to their ability for example the SOAP .wsdl metadata to redirect queries to a different host, than originally intended. |
| Alerts: |
|
( Log in to post comments)
|
|
|