The getlock function in aimage/aimage.cpp in AFFLIB 2.2.8 and earlier allows local users to overwrite arbitrary files via a symlink attack on temporary lock files (aka "time-of-check-time-of-use file race"). NOTE: the researcher has retracted the original advisory, stating that "the portion of vulnerable code is not called in any current version of AFFLIB and is therefore not exploitable.
References

No reference.

History

No history.

cve-icon MITRE

Status: REJECTED

Assigner: mitre

Published: 2007-04-30T22:00:00

Updated: 2018-10-19T14:57:01

Reserved: 2007-04-16T00:00:00

Link: CVE-2007-2056

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Rejected

Published: 2007-04-30T22:19:00.000

Modified: 2023-11-07T02:00:32.323

Link: CVE-2007-2056

cve-icon Redhat

No data.