[10728] in bugtraq

home help back first fref pref prev next nref lref last post

Re: /tmp symlink problems in SuSE Linux 6.1

daemon@ATHENA.MIT.EDU (Marc Heuse)
Sun Jun 6 13:26:11 1999

Mime-Version: 1.0
Content-Type: text/plain; charset=US-ASCII
Content-Transfer-Encoding: 7bit
Message-Id: <19990605200219.578479410@Galois.suse.de>
Date: 	Sat, 5 Jun 1999 22:02:19 +0200
Reply-To: Marc Heuse <marc@SUSE.DE>
From: Marc Heuse <marc@SUSE.DE>
To: BUGTRAQ@NETSPACE.ORG

Hi,

we confirmed the link vulnerablity in the man package.
The culprit is zsoelim which creates the file without looking left and
right. :-(

All linux distributions using man 2.3.10 should be affected.

A fixed package from us will be available soon.

Greets,
	Marc
--
   Marc Heuse, SuSE GmbH, Schanzaeckerstr. 10, 90443 Nuernberg
   E@mail: marc@suse.de  Function: Security Support & Auditing
   "lynx -source http://www.suse.de/~marc/marc.pgp | pgp -fka"
Key fingerprint = B5 07 B6 4E 9C EF 27 EE  16 D9 70 D4 87 B5 63 6C

home help back first fref pref prev next nref lref last post