caml-light <= 0.75 uses mktemp() insecurely, and also does unsafe things in /tmp during make install.
Creating and using insecure temporary files can leave application and system data vulnerable to attack.
Link | Tags |
---|---|
https://seclists.org/oss-sec/2011/q4/249 | mailing list patch exploit third party advisory |
https://vuxml.freebsd.org/freebsd/9dde9dac-08f4-11e1-af36-003067b2972c.html | third party advisory |
http://gnats.netbsd.org/45558 | exploit third party advisory patch |