| Zsh difflog.pl Insecure Temporary Files |
|
|
|
| Written by Staff | |||||
| Monday, 03 December 2007 | |||||
|
A security issue has been reported in Zsh, which can be exploited by
malicious, local users to perform certain actions with escalated
privileges. The security issue is caused due to the Util/difflog.pl script using temporary files in an insecure manner. This can be exploited to overwrite or delete arbitrary files via symlink attacks. The security issue is reported in version 4.3.4. Other versions may also be affected... Solution: Restrict local access to trusted users only.Provided and/or discovered by: Gentoo credits Elias Pipping. Original Advisory: https://bugs.gentoo.org/show_bug.cgi?id=201022 http://secunia.com/advisories/27899/
Powered by a Zone-H(ified) version of AkoComment 3.0! DISCLAIMER: Forum postings are the opinion of the posting author alone, and should not be taken as the opinion of Zone-h. The author is entirely and solely responsible for all content that he/she uploads, posts, or otherwise transmits via the website. Zone-h is not responsible for such content. However, Zone-h shall have the right, but not the obligation, to delete, move, or edit any content that violates this agreement or is otherwise objectionable as determined by Zone-h in its sole discretion and without notice. |
|||||
| < Prev | Next > |
|---|











