Search: Home Bugtraq Vulnerabilities Mailing Lists Jobs Tools Vista

GNU gzexe Temporary File Vulnerability

It has been reported that gzexe uses temporary files insecurely. During execution, an instance of gzexe creates a symbolic link in /tmp with a filename based on its process ID. This creates a race condition that may be exploited by local users to corrupt files writeable by target users.







 

Privacy Statement
Copyright 2008, SecurityFocus