Alerts This Week
Warning Icon 1 541
Alerts This Week
Warning Icon 1 541

Gentoo: 200411-13 Normal: Symlink Overwrite Threat in Portage & Gentoolkit

gentoo
Calendar Grey November 7, 2004
Dist Gentoo Esm H88
Addressing symbolic link complications affecting Gentoo's Portage and Gentoolkit can unlock advanced functionalities. A comprehensive guide to necessary updates is provided within.
dispatch-conf (included in Portage) and qpkg (included in Gentoolkit) are vulnerable to symlink attacks, potentially allowing a local user to overwrite arbitrary files with the rig...

Summary

Gentoo Linux Security Advisory GLSA 200411-13:01 https://security.gentoo.org/ Severity: Normal Title: Portage, Gentoolkit: Temporary file vulnerabilities Date: November 07, 2004 Bugs: #68846, #69147 ID: 200411-13:01

Synopsis ======= dispatch-conf (included in Portage) and qpkg (included in Gentoolkit) are vulnerable to symlink attacks, potentially allowing a local user to overwrite arbitrary files with the rights of the user running the script.
Background ========= Portage is Gentoo's package management tool. The dispatch-conf utility allows for easy rollback of configuration file changes and automatic updates of configurations files never modified by users. Gentoolkit is a collection of Gentoo specific administration scripts, one of which is the portage querying tool qpkg.
Affected packages ================ ------------------------------------------------------------------- Packag...

Read the Full Advisory

Resolution

References

Availability

style>.gentoo_availability{display:block;}

Concerns


Warning: Undefined array key "advisory_info" in /var/www/www.linuxsecurity.com-443/html/tmp/regularlabs/custom_php/3374674_4c9dbbdde36eef04251a4ced7eac4df9 on line 11

Synopsis

Background

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Affected Packages

Impact

Workaround

Related News

Your message here