LWN.net Logo

fedora-business-cards: insecure temporary file usage

Package(s):fedora-business-cards CVE #(s):CVE-2013-0159
Created:September 10, 2013 Updated:September 11, 2013
Description: From the Red Hat bugzilla:

Michael Scherer reported that the fedora-business-cards script used /tmp/fedora-business-cards-buffer.svg as a temporary file, which could be used in symlink attacks to overwrite the contents of a file with write permissions to the person running fedora-business-cards.

Alerts:
Fedora FEDORA-2013-0416 2013-09-09

(Log in to post comments)

Copyright © 2013, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds