Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×

Alerts This Week
Warning Icon 1 514
Alerts This Week
Warning Icon 1 514

Gentoo: GLSA 200508-05 Normal: Heartbeat Symlink Targeting Users

gentoo
Calendar Grey August 7, 2005
Scroller Gentoo
Debian Security Advisory DSA-2005-112 focuses on improper input validation in OpenSSL leading to potential remote exploits.
Heartbeat is vulnerable to symlink attacks, potentially allowing a local user to overwrite arbitrary files.

Summary

Gentoo Linux Security Advisory GLSA 200508-05 https://security.gentoo.org/ Severity: Normal Title: Heartbeat: Insecure temporary file creation Date: August 07, 2005 Bugs: #97175 ID: 200508-05

Synopsis ======= Heartbeat is vulnerable to symlink attacks, potentially allowing a local user to overwrite arbitrary files.
Background ========= Heartbeat is a component of the High-Availability Linux project. It it used to perform death-of-node detection, communications and cluster management.
Affected packages ================ ------------------------------------------------------------------- Package / Vulnerable / Unaffected ------------------------------------------------------------------- 1 sys-cluster/heartbeat < 1.2.3-r1 >= 1.2.3-r1
========== Eric Romang has discovered that Heartbeat insecurely creates temporary files wi...

Read the Full Advisory

Resolution

References

Availability

style>.gentoo_availability{display:block;}

Concerns

Synopsis

Background

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Affected Packages

Impact

Workaround