LWN.net Logo

shorewall: temporary file exploit

Package(s):shorewall CVE #(s):
Created:August 10, 2004 Updated:August 11, 2004
Description: Javier Fernández-Sanguino Peña has discovered an exploitable vulnerability in the way that Shorewall handles temporary files and directories. The vulnerability can allow a non-root user to cause arbitrary files on the system to be overwritten. LEAF Bering and Bering uClibc users are generally not at risk due to the fact that LEAF boxes do not typically allow logins by non-root users. The complete advisory is here.
Alerts:
Mandrake MDKSA-2004:080 2004-08-09

(Log in to post comments)

Copyright © 2008, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds