The getlock function in aimage/aimage.cpp in AFFLIB 2.2.8 and earlier allows local users to overwrite arbitrary files via a symlink attack on temporary lock files (aka "time-of-check-time-of-use file race"). NOTE: the researcher has retracted the original advisory, stating that "the portion of vulnerable code is not called in any current version of AFFLIB and is therefore not exploitable.

Project Subscriptions

No data.

Advisories

No advisories yet.

Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

References

No reference.

History

No history.

Projects

Sign in to view the affected projects.

cve-icon MITRE

Status: REJECTED

Assigner: mitre

Published:

Updated: 2018-10-19T18:57:01.000Z

Reserved: 2007-04-16T04:00:00.000Z

Link: CVE-2007-2056

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Rejected

Published: 2007-04-30T22:19:00.000

Modified: 2023-11-07T02:00:32.323

Link: CVE-2007-2056

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.

Weaknesses

No weakness.