[<prev] [next>] [thread-next>] [month] [year] [list]
Date: Thu, 20 Nov 2008 21:32:53 -0600
From: Raphael Geissert <atomo64+debian@...il.com>
To: oss-security@...ts.openwall.com
Subject: CVE id request: chm2pdf insecure temporary files usage
-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1
Hello,
Versions 0.9 and 0.9.1 of chm2pdf allow local users to overwrite arbitrary files
via a symlink attacks on /tmp/chm2pdf
More information at http://bugs.debian.org/501959
Could a CVE id be assigned please?
Thanks in advance.
Cheers,
- --
Raphael Geissert - Debian Maintainer
www.debian.org - get.debian.net
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.4.9 (GNU/Linux)
iEYEARECAAYFAkkmK+YACgkQYy49rUbZzlrDlgCeOsa92d/XCpTjT0b9EikJwme0
C6oAoJhWLgQjNn0U/8BgI3dy/s5Q1Eom
=w0+u
-----END PGP SIGNATURE-----
Please check out the
Open Source Software Security Wiki, which is counterpart to this
mailing list.
Powered by Openwall GNU/*/Linux -
Powered by OpenVZ