vobcopy 0.5.14 allows local users to append data to an arbitrary file, or create an arbitrary new file, via a symlink attack on the (1) /tmp/vobcopy.bla or (2) /tmp/vobcopy_0.5.14.log temporary file.
References
Configurations
Configuration 1 (hide)
AND |
|
Information
Published : 2007-10-30 14:46
Updated : 2017-07-28 18:33
NVD link : CVE-2007-5718
Mitre link : CVE-2007-5718
JSON object : View
CWE
CWE-59
Improper Link Resolution Before File Access ('Link Following')
Products Affected
debian
- debian_linux
vobcopy
- vobcopy