msxlsview.sh in xlsview for catdoc 0.91 and earlier allows local users to overwrite arbitrary files via a symlink attack on predictable temporary file names ("word$$.html").
Link | Tags |
---|---|
http://www.osvdb.org/11193 | vdb entry |
http://www.securityfocus.com/bid/11560 | vdb entry |
http://secunia.com/advisories/13021/ | third party advisory |
http://secunia.com/advisories/13022/ | third party advisory |
https://exchange.xforce.ibmcloud.com/vulnerabilities/16335 | vdb entry |
http://bugs.debian.org/cgi-bin/bugreport.cgi?archive=no&bug=183525 | |
http://www.debian.org/security/2004/dsa-575 | vendor advisory |