AllCommerce with debugging enabled in EnGarde Secure Linux 1.0.1 creates temporary files with predictable names, which allows local users to modify files via a symlink attack.
Link | Tags |
---|---|
http://www.linuxsecurity.com/advisories/other_advisory-1492.html | patch vendor advisory |
https://exchange.xforce.ibmcloud.com/vulnerabilities/6830 | vdb entry |
http://www.securityfocus.com/bid/3016 | vdb entry |