noweb: insecure temporary files
| Package(s): | noweb | CVE #(s): | CAN-2003-0381 | ||||||||
| Created: | June 17, 2003 | Updated: | June 28, 2003 | ||||||||
| Description: | Jakob Lell discovered a bug in the 'noroff' script included in noweb whereby a temporary file was created insecurely. During a review, several other instances of this problem were found and fixed. Any of these bugs could be exploited by a local user to overwrite arbitrary files owned by the user invoking the script. | ||||||||||
| Alerts: |
| ||||||||||
