LWN.net Logo

Scrollkeeper temporary file vulnerability

Package(s):scrollkeeper CVE #(s):CAN-2002-0662
Created:September 4, 2002 Updated:September 4, 2002
Description: There is a tempfile vulnerability in ScrollKeeper versions between 0.3 and 0.3.11.

The scrollkeeper-get-cl command generates temporary files with predictable names and follows symbolic links. "These files are created when a user logs in to a GNOME session and are created as the user who logged in. This means an attacker with local access can easily create and overwrite files as another user." For more information see this security advisory from Spybreak.

ScrollKeeper is a cataloging system for documentation on open systems. It manages documentation metadata (as specified by the Open Source Metadata Framework(OMF)) and provides a simple API to allow help browsers to find, sort, and search the document catalog.
Alerts:
Gentoo scrollkeeper-20020904 2002-09-04
Debian DSA-160-1 2002-09-03
Red Hat RHSA-2002:186-07 2002-08-28

(Log in to post comments)

Copyright © 2008, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds