Hi! This got a CAN number assigned. Can you please mention it in the changelog when you fix this?
Thanks, Martin ----- Forwarded message from "Steven M. Christey" <[EMAIL PROTECTED]> ----- Date: Tue, 23 Aug 2005 14:53:06 -0400 (EDT) From: "Steven M. Christey" <[EMAIL PROTECTED]> To: [EMAIL PROTECTED], [EMAIL PROTECTED] Cc: [EMAIL PROTECTED] Subject: CAN-2005-2672 assigned to pwmconfig symlink X-Spam-Status: No, score=1.4 required=4.0 tests=AWL,BAYES_50 autolearn=no version=3.0.3 FYI... ====================================================== Candidate: CAN-2005-2672 URL: http://cve.mitre.org/cgi-bin/cvename.cgi?name=CAN-2005-2672 Reference: BID:14624 Reference: URL:http://www.securityfocus.com/bid/14624 Reference: UBUNTU:USN-172-1 Reference: URL:http://www.ubuntulinux.org/support/documentation/usn/usn-172-1 Reference: CONFIRM:http://secure.netroedge.com/~lm78/cvs/lm_sensors2/CHANGES pwmconfig in LM_sensors before 2.9.1 creates temporary files insecurely, which allows local users to overwrite arbitrary files via a symlink attack on the fancontrol temporary file. ----- End forwarded message ----- -- Martin Pitt http://www.piware.de Ubuntu Developer http://www.ubuntu.com Debian Developer http://www.debian.org
signature.asc
Description: Digital signature