Alerts This Week
Warning Icon 1 681
Alerts This Week
Warning Icon 1 681

Gentoo: GLSA-200903-36 Critical: Apache Struts Vulnerability

gentoo
Calendar Grey March 23, 2009
Dist Gentoo Esm H88
Muttprint on Gentoo has vulnerabilities due to improper file permissions, allowing symlink attacks. It is recommended to upgrade to mitigate these issues
An insecure temporary file usage in Muttprint allows for symlink attacks.

Summary

Gentoo Linux Security Advisory GLSA 200903-35 https://security.gentoo.org/ Severity: Normal Title: Muttprint: Insecure temporary file usage Date: March 23, 2009 Bugs: #250554 ID: 200903-35

Synopsis ======= An insecure temporary file usage in Muttprint allows for symlink attacks.
Background ========= Muttprint formats the output of mail clients to a good-looking printing using LaTeX.
Affected packages ================ ------------------------------------------------------------------- Package / Vulnerable / Unaffected ------------------------------------------------------------------- 1 app-misc/muttprint < 0.72d-r1 >= 0.72d-r1
========== Dmitry E. Oboukhov reported an insecure usage of the temporary file "/tmp/muttprint.log" in the muttprint script.
Impact ===== A local attacker could perform symlink attacks to overw...

Read the Full Advisory

Resolution

References

Availability

style>.gentoo_availability{display:block;}

Concerns

Synopsis

Background

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Affected Packages

Impact

Workaround

Related News

Your message here