Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×
Gentoo Linux Security Advisory GLSA 200502-01
https://security.gentoo.org/
Severity: Normal
Title: FireHOL: Insecure temporary file creation
Date: February 01, 2005
Bugs: #79330
ID: 200502-01
Synopsis
=======
FireHOL is vulnerable to symlink attacks, potentially allowing a local
user to overwrite arbitrary files.
Background
=========
FireHOL is an iptables rules generator.
Affected packages
================
-------------------------------------------------------------------
Package / Vulnerable / Unaffected
-------------------------------------------------------------------
1 net-firewall/firehol < 1.224 >= 1.224
==========
FireHOL insecurely creates temporary files with predictable names.
Impact
=====
A local attacker could create malicious symbolic links to arbitrary
system files. When FireHOL is executed...
style>.gentoo_availability{display:block;}
Get the latest Linux and open source security news straight to your inbox.