Описание
The ispell_op function in ee on FreeBSD 4.10 to 6.0 uses predictable filenames and does not confirm which file is being written, which allows local users to overwrite arbitrary files via a symlink attack when ee invokes ispell.
Релиз | Статус | Примечание |
---|---|---|
dapper | released | 1:1.4.2-5 |
devel | released | 1:1.4.2-5 |
edgy | released | 1:1.4.2-5 |
feisty | released | 1:1.4.2-5 |
gutsy | released | 1:1.4.2-5 |
upstream | needs-triage |
Показывать по
Ссылки на источники
2.1 Low
CVSS2
Связанные уязвимости
The ispell_op function in ee on FreeBSD 4.10 to 6.0 uses predictable filenames and does not confirm which file is being written, which allows local users to overwrite arbitrary files via a symlink attack when ee invokes ispell.
The ispell_op function in ee on FreeBSD 4.10 to 6.0 uses predictable f ...
The ispell_op function in ee on FreeBSD 4.10 to 6.0 uses predictable filenames and does not confirm which file is being written, which allows local users to overwrite arbitrary files via a symlink attack when ee invokes ispell.
2.1 Low
CVSS2