Util/difflog.pl in zsh 4.3.4 allows local users to overwrite arbitrary files via a symlink attack on temporary files.
Weaknesses in this category are related to the management of permissions, privileges, and other security features that are used to perform access control.
Link | Tags |
---|---|
http://osvdb.org/42481 | vdb entry |
http://www.zsh.org/mla/workers/2007/msg01066.html | mailing list |
http://www.zsh.org/mla/workers/2007/msg01060.html | mailing list |
https://bugs.gentoo.org/show_bug.cgi?id=201022 | |
http://www.securityfocus.com/bid/26674 | vdb entry |
https://exchange.xforce.ibmcloud.com/vulnerabilities/38812 | vdb entry |
http://www.zsh.org/mla/workers/2007/msg01065.html | mailing list |
http://secunia.com/advisories/27899 | third party advisory |