Ken Stevens ispell Symbolic Link...

- AV AC AU C I A
发布: 2001-06-05
修订: 2025-04-13

A vulnerability exists in versions of ispell, involving the way gnomerpm handles tmp files. ispell creates temporary files in the world-writeable /tmp directory with preditable filenames. It is possible for a malicious user to create symbolic links in /tmp with guessed/predicted filenames, knowing in advance that ispell will be run by a privileged user. When this happens, the files pointed to by the correctly guessed symbolic links will be overwritten.

0%
暂无可用Exp或PoC
当前有0条受影响产品信息