Bournal before 1.4.1 allows local users to overwrite arbitrary files via a symlink attack on unspecified temporary files associated with a --hack_the_gibson update check.
The product attempts to access a file based on the filename, but it does not properly prevent that filename from identifying a link or shortcut that resolves to an unintended resource.
Link | Tags |
---|---|
http://www.securityfocus.com/archive/1/509685/100/0/threaded | mailing list |
http://lists.fedoraproject.org/pipermail/package-announce/2010-March/036701.html | vendor advisory |
http://lists.fedoraproject.org/pipermail/package-announce/2010-March/036764.html | vendor advisory |
http://secunia.com/advisories/38554 | third party advisory vendor advisory |
http://secunia.com/secunia_research/2010-6/ | vendor advisory |
http://secunia.com/advisories/38814 | third party advisory |
http://lists.fedoraproject.org/pipermail/package-announce/2010-March/036697.html | vendor advisory |
http://www.securityfocus.com/bid/38353 | vdb entry |