Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×

Alerts This Week
Warning Icon 1 524
Alerts This Week
Warning Icon 1 524

Gentoo: GLSA-202310-34 Moderate: Filezilla RCE Security Flaw Announced

gentoo
Calendar Grey September 9, 2009
Scroller Gentoo
Gentoo Linux Advisory GLSA 202203-11 highlights a vulnerability in OpenSSH that poses a medium severity risk; updates recommended.
An insecure temporary file usage has been reported in TkMan, allowing for symlink attacks.

Summary

Gentoo Linux Security Advisory GLSA 200909-07 https://security.gentoo.org/ Severity: Normal Title: TkMan: Insecure temporary file usage Date: September 09, 2009 Bugs: #247540 ID: 200909-07

Synopsis ======= An insecure temporary file usage has been reported in TkMan, allowing for symlink attacks.
Background ========= TkMan is a graphical, hypertext manual page and Texinfo browser for UNIX.
Affected packages ================ ------------------------------------------------------------------- Package / Vulnerable / Unaffected ------------------------------------------------------------------- 1 app-text/tkman < 2.2-r1 >= 2.2-r1
========== Dmitry E. Oboukhov reported that TkMan does not handle the "/tmp/tkman#####" and "/tmp/ll" temporary files securely.
Impact ===== A local attacker could perform symlink attacks...

Read the Full Advisory

Resolution

References

Availability

style>.gentoo_availability{display:block;}

Concerns

Synopsis

Background

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Affected Packages

Impact

Workaround