Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×

Alerts This Week
Warning Icon 1 523
Alerts This Week
Warning Icon 1 523

Gentoo: GLSA-202305-05 Moderate: OpenSSL SSLv2 Protocol Vulnerability

gentoo
Calendar Grey September 9, 2009
Scroller Gentoo
GCC-XML has identified insecure handling of temporary files classified with a moderate severity. This vulnerability may be subject to symlink attacks.
An insecure temporary file usage has been reported in GCC-XML allowing for symlink attacks.

Summary

Gentoo Linux Security Advisory GLSA 200909-11 https://security.gentoo.org/ Severity: Normal Title: GCC-XML: Insecure temporary file usage Date: September 09, 2009 Bugs: #245765 ID: 200909-11

Synopsis ======= An insecure temporary file usage has been reported in GCC-XML allowing for symlink attacks.
Background ========= GCC-XML is an XML output extension to the C++ front-end of GCC.
Affected packages ================ ------------------------------------------------------------------- Package / Vulnerable / Unaffected ------------------------------------------------------------------- 1 dev-cpp/gccxml < 0.9.0_pre20090516 >= 0.9.0_pre20090516
========== Dmitry E. Oboukhov reported that find_flags in GCC-XML does not handle "/tmp/*.cxx" temporary files securely.
Impact ===== A local attacker could perform symlink attacks to overwrite ...

Read the Full Advisory

Resolution

References

Availability

style>.gentoo_availability{display:block;}

Concerns

Synopsis

Background

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Affected Packages

Impact

Workaround