The getlock function in aimage/aimage.cpp in AFFLIB 2.2.8 and earlier allows local users to overwrite arbitrary files via a symlink attack on temporary lock files (aka "time-of-check-time-of-use file race"). NOTE: the researcher has retracted the original advisory, stating that "the portion of vulnerable code is not called in any current version of AFFLIB and is therefore not exploitable.
Metrics
Affected Vendors & Products
References
No reference.
History
No history.
MITRE
Status: REJECTED
Assigner: mitre
Published: 2007-04-30T22:00:00
Updated: 2018-10-19T14:57:01
Reserved: 2007-04-16T00:00:00
Link: CVE-2007-2056
Vulnrichment
No data.
NVD
Status : Rejected
Published: 2007-04-30T22:19:00.000
Modified: 2023-11-07T02:00:32.323
Link: CVE-2007-2056
Redhat
No data.