Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×

Alerts This Week
Warning Icon 1 492
Alerts This Week
Warning Icon 1 492

Gentoo: GLSA-200709-04 Normal: po4a Insecure File Creation Risk

gentoo
Calendar Grey September 13, 2007
Scroller Gentoo
Gentoo Linux GLSA 202210-15 alerts about a medium severity vulnerability in libXYZ, enabling potential symlink exploitation necessitating a software patch.
A vulnerability has been discovered in po4a, allowing for a symlink attack.

Summary

Gentoo Linux Security Advisory GLSA 200709-04 https://security.gentoo.org/ Severity: Normal Title: po4a: Insecure temporary file creation Date: September 13, 2007 Bugs: #189440 ID: 200709-04

Synopsis ======= A vulnerability has been discovered in po4a, allowing for a symlink attack.
Background ========= po4a is a set of tools for helping with the translation of documentation.
Affected packages ================ ------------------------------------------------------------------- Package / Vulnerable / Unaffected ------------------------------------------------------------------- 1 app-text/po4a < 0.32-r1 >= 0.32-r1
========== The po4a development team reported a race condition in the gettextize() function when creating the file "/tmp/gettextization.failed.po".
Impact ===== A local attacker could perform a symlin...

Read the Full Advisory

Resolution

References

Availability

style>.gentoo_availability{display:block;}

Concerns

Synopsis

Background

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Affected Packages

Impact

Workaround