Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×

Alerts This Week
Warning Icon 1 507
Alerts This Week
Warning Icon 1 507

Gentoo: GLSA 202310-01 Critical: GnuPG Vulnerability Exploit Risk

gentoo
Calendar Grey October 5, 2005
Scroller Gentoo
Gentoo GLSA 200610-05 tackles the vulnerabilities found in LibXML2 that allow remote attackers to execute arbitrary code through crafted XML files.
Texinfo is vulnerable to symlink attacks, potentially allowing a local user to overwrite arbitrary files.

Summary

Gentoo Linux Security Advisory GLSA 200510-04 https://security.gentoo.org/ Severity: Normal Title: Texinfo: Insecure temporary file creation Date: October 05, 2005 Bugs: #106105 ID: 200510-04

Synopsis ======= Texinfo is vulnerable to symlink attacks, potentially allowing a local user to overwrite arbitrary files.
Background ========= Texinfo is the official documentation system created by the GNU project.
Affected packages ================ ------------------------------------------------------------------- Package / Vulnerable / Unaffected ------------------------------------------------------------------- 1 sys-apps/texinfo < 4.8-r1 >= 4.8-r1
========== Frank Lichtenheld has discovered that the "sort_offline()" function in texindex insecurely creates temporary files with predictable filenames.
Impact ===== A l...

Read the Full Advisory

Resolution

References

Availability

style>.gentoo_availability{display:block;}

Concerns

Synopsis

Background

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Affected Packages

Impact

Workaround