Alerts This Week
Warning Icon 1 714
Alerts This Week
Warning Icon 1 714

Gentoo: GLSA 200909-10 Normal: LMBench Insecure File Risk

gentoo
Calendar Grey September 9, 2009
Dist Gentoo Esm H88
Gentoo GLSA 202310-15 uncovers vulnerabilities in XYZBench due to unsafe file handling, potentially facilitating symlink exploits. Discover further details.
Multiple insecure temporary file usage issues have been reported in LMBench, allowing for symlink attacks.

Summary

Gentoo Linux Security Advisory GLSA 200909-10 https://security.gentoo.org/ Severity: Normal Title: LMBench: Insecure temporary file usage Date: September 09, 2009 Bugs: #246015 ID: 200909-10

Synopsis ======= Multiple insecure temporary file usage issues have been reported in LMBench, allowing for symlink attacks.
Background ========= LMBench is a suite of simple, portable benchmarks for UNIX platforms.
Affected packages ================ ------------------------------------------------------------------- Package / Vulnerable / Unaffected ------------------------------------------------------------------- 1 app-benchmarks/lmbench <= 3 Vulnerable! ------------------------------------------------------------------- NOTE: Certain packages are still vulnerable. Users should migrate to another package if one is available or wait for the existing packages to be marked stable by their architecture maintainers.
========== Dmitry E. Oboukhov reported that the rccs and STUFF scripts do not handle "/tmp/sdiff.#####" temporary files securely. NOTE: There might be further occurances of insecure temporary file usage.
Impac...

Read the Full Advisory

Resolution

References

Availability

style>.gentoo_availability{display:block;}

Concerns

Synopsis

Background

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Affected Packages

Impact

Workaround

Your message here