The pre-install script in texlive 3.1.20140525_r34255.fc21 as packaged in Fedora 21 and rpm, and texlive 6.20131226_r32488.fc20 and rpm allows local users to delete arbitrary files via a crafted file in the user's home directory.
Weaknesses in this category are related to the management of permissions, privileges, and other security features that are used to perform access control.
Link | Tags |
---|---|
http://lists.fedoraproject.org/pipermail/package-announce/2015-April/154198.html | third party advisory vendor advisory |
http://www.securityfocus.com/bid/72826 | vdb entry third party advisory |
http://lists.fedoraproject.org/pipermail/package-announce/2015-April/154424.html | third party advisory vendor advisory |
http://www.openwall.com/lists/oss-security/2015/02/27/6 | third party advisory mailing list |
https://bugzilla.redhat.com/show_bug.cgi?id=1197082 | issue tracking third party advisory |