The ps2epsi extension shell script (ps2epsi.sh) in Inkscape before 0.41 allows local users to overwrite arbitrary files via a symlink attack on the tmpepsifile.epsi temporary file.
Link | Tags |
---|---|
http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=321501 | |
http://secunia.com/advisories/17882 | third party advisory |
http://secunia.com/advisories/16343 | third party advisory |
https://usn.ubuntu.com/223-1/ | vendor advisory |
http://secunia.com/advisories/17886 | third party advisory |
http://www.debian.org/security/2005/dsa-916 | vendor advisory |
http://www.securityfocus.com/bid/14522 | vdb entry patch |