|
Message-ID: <gg5a6c$gs5$4@ger.gmane.org> Date: Thu, 20 Nov 2008 21:32:53 -0600 From: Raphael Geissert <atomo64+debian@...il.com> To: oss-security@...ts.openwall.com Subject: CVE id request: chm2pdf insecure temporary files usage -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 Hello, Versions 0.9 and 0.9.1 of chm2pdf allow local users to overwrite arbitrary files via a symlink attacks on /tmp/chm2pdf More information at http://bugs.debian.org/501959 Could a CVE id be assigned please? Thanks in advance. Cheers, - -- Raphael Geissert - Debian Maintainer www.debian.org - get.debian.net -----BEGIN PGP SIGNATURE----- Version: GnuPG v1.4.9 (GNU/Linux) iEYEARECAAYFAkkmK+YACgkQYy49rUbZzlrDlgCeOsa92d/XCpTjT0b9EikJwme0 C6oAoJhWLgQjNn0U/8BgI3dy/s5Q1Eom =w0+u -----END PGP SIGNATURE-----
Powered by blists - more mailing lists
Please check out the Open Source Software Security Wiki, which is counterpart to this mailing list.
Confused about mailing lists and their use? Read about mailing lists on Wikipedia and check out these guidelines on proper formatting of your messages.