fedup 0.9.0 in Fedora 19, 20, and 21 uses a temporary directory with a static name for its download cache, which allows local users to cause a denial of service (prevention of system updates).
This entry has been deprecated. It was originally used for organizing the Development View (CWE-699) and some other views, but it introduced unnecessary complexity and depth to the resulting tree.
Link | Tags |
---|---|
http://lists.fedoraproject.org/pipermail/package-announce/2014-November/141698.html | vendor advisory |
http://lists.fedoraproject.org/pipermail/package-announce/2014-November/142933.html | vendor advisory |
http://lists.fedoraproject.org/pipermail/package-announce/2014-November/142698.html | vendor advisory |
https://github.com/wgwoods/fedup/issues/44 | patch vendor advisory |
https://bugzilla.redhat.com/show_bug.cgi?id=1066679 | vendor advisory |
http://www.securityfocus.com/bid/70874 | vdb entry |