Alerts This Week
Warning Icon 1 626
Alerts This Week
Warning Icon 1 626

Gentoo: GLSA-200709-04 Normal: po4a Insecure File Creation Risk

gentoo
Calendar Grey September 13, 2007
Dist Gentoo Esm H88
Gentoo Linux GLSA 202210-15 alerts about a medium severity vulnerability in libXYZ, enabling potential symlink exploitation necessitating a software patch.
A vulnerability has been discovered in po4a, allowing for a symlink attack.

Summary

Gentoo Linux Security Advisory GLSA 200709-04 https://security.gentoo.org/ Severity: Normal Title: po4a: Insecure temporary file creation Date: September 13, 2007 Bugs: #189440 ID: 200709-04

Synopsis ======= A vulnerability has been discovered in po4a, allowing for a symlink attack.
Background ========= po4a is a set of tools for helping with the translation of documentation.
Affected packages ================ ------------------------------------------------------------------- Package / Vulnerable / Unaffected ------------------------------------------------------------------- 1 app-text/po4a < 0.32-r1 >= 0.32-r1
========== The po4a development team reported a race condition in the gettextize() function when creating the file "/tmp/gettextization.failed.po".
Impact ===== A local attacker could perform a symlin...

Read the Full Advisory

Resolution

References

Availability

style>.gentoo_availability{display:block;}

Concerns


Warning: Undefined array key "advisory_info" in /var/www/www.linuxsecurity.com-443/html/tmp/regularlabs/custom_php/33851_4c9dbbdde36eef04251a4ced7eac4df9 on line 11

Synopsis

Background

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Affected Packages

Impact

Workaround

Related News

Your message here