babiloo 2.0.9 before 2.0.11 creates temporary files with predictable names when downloading and unpacking dictionary files, allowing a local attacker to overwrite arbitrary files.
The product downloads source code or an executable from a remote location and executes the code without sufficiently verifying the origin and integrity of the code.
Link | Tags |
---|---|
https://security-tracker.debian.org/tracker/CVE-2010-3440 | third party advisory |
https://access.redhat.com/security/cve/cve-2010-3440 | broken link |
https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=591995 | third party advisory mailing list |