LWN.net Logo

esearch: insecure temp file handling

Package(s):esearch CVE #(s):
Created:July 1, 2004 Updated:July 6, 2004
Description: The eupdatedb utility that is part of esearch can allow a symbolic link to be created in /tmp, making it possible for users to create arbitrary files.
Alerts:
Gentoo 200407-01 2004-07-01

(Log in to post comments)

Copyright © 2008, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds