The xdvizilla script in tetex-bin 2.0.2 creates temporary files with predictable file names, which allows local users to overwrite arbitrary files via a symlink attack.
References
Link | Resource |
---|---|
http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=286370 | Vendor Advisory |
http://www.securityfocus.com/bid/12100 | Patch Vendor Advisory |
http://marc.info/?l=bugtraq&m=110383942014839&w=2 | |
https://exchange.xforce.ibmcloud.com/vulnerabilities/18708 |
Information
Published : 2004-12-22 21:00
Updated : 2017-07-10 18:30
NVD link : CVE-2004-1336
Mitre link : CVE-2004-1336
JSON object : View
CWE
Products Affected
debian
- tetex-bin
gentoo
- linux