GLSA Advocate
Joined: 12 May 2004 Posts: 2663
|
Posted: Mon Dec 10, 2007 12:26 am Post subject: [ GLSA 200712-07 ] Lookup: Insecure temporary file creation |
|
|
Gentoo Linux Security Advisory
Title: Lookup: Insecure temporary file creation (GLSA 200712-07)
Severity: normal
Exploitable: local
Date: December 09, 2007
Bug(s): #197306
ID: 200712-07
Synopsis
Lookup uses temporary files in an insecure manner, allowing for a symlink attack.
Background
Lookup is a search interface to books and dictionnaries for Emacs.
Affected Packages
Package: app-emacs/lookup
Vulnerable: < 1.4.1
Unaffected: >= 1.4.1
Architectures: All supported architectures
Description
Tatsuya Kinoshita reported that the ndeb-binary function does not handle temporay files correctly.
Impact
A local attacker could use a symlink attack to overwrite files with the privileges of the user running Lookup.
Workaround
There is no known workaround at this time.
Resolution
All Lookup users should upgrade to the latest version: Code: | # emerge --sync
# emerge --ask --oneshot --verbose ">=app-emacs/lookup-1.4.1" |
References
CVE-2007-0237 |
|