diff options
author | simon <simon@FreeBSD.org> | 2005-02-19 06:37:34 +0800 |
---|---|---|
committer | simon <simon@FreeBSD.org> | 2005-02-19 06:37:34 +0800 |
commit | bec5f226e2e0d389611e0f0cb3e39b559e7d3d45 (patch) | |
tree | 778bfcd79c1e037fd670853cb0e1f964fe917b7f /security/vuxml | |
parent | caa66166d78896b0276b44efcb3dcd25d4848621 (diff) | |
download | freebsd-ports-gnome-bec5f226e2e0d389611e0f0cb3e39b559e7d3d45.tar.gz freebsd-ports-gnome-bec5f226e2e0d389611e0f0cb3e39b559e7d3d45.tar.zst freebsd-ports-gnome-bec5f226e2e0d389611e0f0cb3e39b559e7d3d45.zip |
Document insecure temporary file creation in kdelibs.
Diffstat (limited to 'security/vuxml')
-rw-r--r-- | security/vuxml/vuln.xml | 30 |
1 files changed, 30 insertions, 0 deletions
diff --git a/security/vuxml/vuln.xml b/security/vuxml/vuln.xml index 5b5fd9fd0cdd..89fe009aa64f 100644 --- a/security/vuxml/vuln.xml +++ b/security/vuxml/vuln.xml @@ -32,6 +32,36 @@ EVEN IF ADVISED OF THE POSSIBILITY OF SUCH DAMAGE. --> <vuxml xmlns="http://www.vuxml.org/apps/vuxml-1"> + <vuln vid="29dd0065-81fa-11d9-a9e7-0001020eed82"> + <topic>kdelibs -- insecure temporary file creation</topic> + <affects> + <package> + <name>kdelibs</name> + <name>ja-kdelibs</name> + <range><lt>3.3.2_5</lt></range> + </package> + </affects> + <description> + <body xmlns="http://www.w3.org/1999/xhtml"> + <p>Davide Madrisan reports:</p> + <blockquote cite="http://marc.theaimsgroup.com/?l=bugtraq&m=110814653804757"> + <p>The `dcopidlng' script in the KDE library package + (kdelibs-3.3.2/dcop/dcopidlng/dcopidlng) creates temporary + files in a unsecure manner.</p> + </blockquote> + </body> + </description> + <references> + <cvename>CAN-2005-0365</cvename> + <url>http://bugs.kde.org/show_bug.cgi?id=97608</url> + <mlist msgid="200502110916.48921.davide.madrisan@qilinux.it">http://marc.theaimsgroup.com/?l=bugtraq&m=110814653804757</mlist> + </references> + <dates> + <discovery>2005-01-21</discovery> + <entry>2005-02-18</entry> + </dates> + </vuln> + <vuln vid="74c86a29-81ef-11d9-a9e7-0001020eed82"> <topic>bidwatcher -- format string vulnerability</topic> <affects> |