inkscape: insecure temp files
| Package(s): | inkscape | CVE #(s): | CVE-2005-3885 | ||||
| Created: | December 5, 2005 | Updated: | December 7, 2005 | ||||
| Description: | Javier Fernández-Sanguino Peña discovered that Inkscape's ps2epsi.sh script, which converts PostScript files to Encapsulated PostScript format, creates a temporary file in an insecure way. A local attacker could exploit this with a symlink attack to create or overwrite arbitrary files with the privileges of the user running Inkscape. | ||||||
| Alerts: |
| ||||||
