skk (Simple Kana to Kanji conversion program) 12.1 and earlier, and the ddskk package which is based on skk, creates temporary files insecurely, which allows local users to overwrite arbitrary files.
Link | Tags |
---|---|
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A28 | vdb entry signature |
http://www.redhat.com/support/errata/RHSA-2003-242.html | vendor advisory |
http://www.debian.org/security/2003/dsa-343 | patch vendor advisory |