A symlink issue exists in Iceweasel-firegpg before 0.6 due to insecure tempfile handling.
The product attempts to access a file based on the filename, but it does not properly prevent that filename from identifying a link or shortcut that resolves to an unintended resource.
Link | Tags |
---|---|
https://security-tracker.debian.org/tracker/CVE-2008-7273 | third party advisory |
https://www.openwall.com/lists/oss-security/2011/01/14/2 | third party advisory mailing list |
https://vulners.com/securityvulns/SECURITYVULNS:DOC:20757?utm_source=securityvulns&utm_medium=redirect | third party advisory |