From 9394221112c9a1be3157df18ed2561d7e4e7de2b Mon Sep 17 00:00:00 2001 From: remko Date: Mon, 10 Apr 2006 19:11:14 +0000 Subject: Document f2c -- insecure temporary files. It is not very clear to me to see what version is fixed. The one fixing this port should import the latest available one which is fixed. --- security/vuxml/vuln.xml | 29 +++++++++++++++++++++++++++++ 1 file changed, 29 insertions(+) (limited to 'security/vuxml') diff --git a/security/vuxml/vuln.xml b/security/vuxml/vuln.xml index bdf8d3b46fe..089e8d382d2 100644 --- a/security/vuxml/vuln.xml +++ b/security/vuxml/vuln.xml @@ -34,6 +34,35 @@ Note: Please add new entries to the beginning of this file. --> + + f2c -- insecure temporary files + + + f2c + 0 + + + + +

Javier Fernandez-Sanguino Pena reports two temporary file + vulnerability within f2c. The vulnerabilities are caused + due to weak temporary file handling. An attacker could + create an symbolic link, causing a local user running f2c + to overwrite the symlinked file. This could give the + attacker elevated privileges.

+ +
+ + 1280 + CAN-2005-0017 + CAN-2005-0018 + + + 2005-01-27 + 2006-04-10 + +
+ mplayer -- Multiple integer overflows -- cgit