The xdvizilla script in tetex-bin 2.0.2 creates temporary files with predictable file names, which allows local users to overwrite arbitrary files via a symlink attack.
Link | Tags |
---|---|
http://www.securityfocus.com/bid/12100 | vdb entry patch vendor advisory |
https://exchange.xforce.ibmcloud.com/vulnerabilities/18708 | vdb entry |
http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=286370 | vendor advisory |
http://marc.info/?l=bugtraq&m=110383942014839&w=2 | mailing list |