netpbm is graphics conversion toolkit made up of a large number of
single-purpose programs. Many of these programs were found to create
temporary files in an insecure manner, which could allow a local
attacker to overwrite files with the privileges of the user invoking a
vulnerable netpbm tool.
Posted Feb 12, 2004 6:01 UTC (Thu) by mattdm (subscriber, #18)
[Link]
Note that the red hat update for netpbm requires a newer version of mktemp than is in RHL 9. You'll want to build and install the one from Fedora Core 1 or somewhere, or wait until they update the update.