Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×
Gentoo Linux Security Advisory GLSA 200501-43
https://security.gentoo.org/
Severity: Normal
Title: f2c: Insecure temporary file creation
Date: January 30, 2005
Bugs: #79725
ID: 200501-43
Synopsis
=======
f2c is vulnerable to symlink attacks, potentially allowing a local user
to overwrite arbitrary files.
Background
=========
f2c is a Fortran to C translator. Portage uses this package in some
ebuilds to build Fortran sources.
Affected packages
================
-------------------------------------------------------------------
Package / Vulnerable / Unaffected
-------------------------------------------------------------------
1 dev-lang/f2c <= 20030320 >= 20030320-r1
==========
Javier Fernandez-Sanguino Pena from the Debian Security Audit Team
discovered that f2c creates temporary files in world-writeable
directories with predictable names.
Impact
...
style>.gentoo_availability{display:block;}
Get the latest Linux and open source security news straight to your inbox.