LWN.net Logo

fabric: symlink attack

Package(s):fabric CVE #(s):CVE-2011-2185
Created:July 12, 2011 Updated:July 13, 2011
Description: From the Red Hat bugzilla:

It was found that fabric, a simple Pythonic remote deployment tool, used insecure way for creation of temporary files, when uploading template text files and project files to a remote system. A local attacker could use this flaw to conduct symlink attacks to upload sensitive information to remote host or to overwrite certain local system files.

Alerts:
Fedora FEDORA-2011-8964 2011-07-01

(Log in to post comments)

Copyright © 2013, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds