Description
(1) debian/postrm and (2) debian/localepurge.config in localepurge before 0.7.3.2 use tempfile to create a safe temporary file but appends a suffix to the original filename and writes to this new filename, which allows local users to overwrite arbitrary files via a symlink attack on the new filename.
No analysis available yet.
Remediation
No remediation available yet.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2014-1712 | (1) debian/postrm and (2) debian/localepurge.config in localepurge before 0.7.3.2 use tempfile to create a safe temporary file but appends a suffix to the original filename and writes to this new filename, which allows local users to overwrite arbitrary files via a symlink attack on the new filename. |
References
History
No history.
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2024-08-06T09:50:09.783Z
Reserved: 2014-01-22T00:00:00.000Z
Link: CVE-2014-1638
No data.
Status : Modified
Published: 2014-01-28T00:55:04.130
Modified: 2026-04-29T01:13:23.040
Link: CVE-2014-1638
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD