In Eternal Terminal 6.2.1, etserver and etclient have predictable logfile names in /tmp.
The product specifies permissions for a security-critical resource in a way that allows that resource to be read or modified by unintended actors.
Link | Tags |
---|---|
https://github.com/MisterTea/EternalTerminal/issues/555 | issue tracking third party advisory patch |
https://github.com/MisterTea/EternalTerminal/pull/556 | exploit third party advisory patch |
http://www.openwall.com/lists/oss-security/2023/02/16/1 | mailing list |
https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/U6MO4FSKYNSAJVUXYP7LRY7ARUIGKBFL/ | vendor advisory |
https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/2RY6PKBU73I45L6YWNYCUK2XBEXEFX7L/ | vendor advisory |
https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/NYODHZECXYFC2BNODZPZXZAXOKGMCYAP/ | vendor advisory |