Bug#497452: nfdump: vulnerable to symlink attacks

2008-09-02 Thread Andreas Putzo
tags 497452 patch thanks Hi, On Sep 01 22:26, Andreas Putzo wrote: > Package: nfdump > Version: 1.5.7-4 > Severity: grave > Tags: security > > nfdump in its default installation starts nfcapd as a daemon that > creates a file in /var/tmp/nfcapd.current. as well as > /var/tmp/nfcapd.. These fil

Bug#497452: nfdump: vulnerable to symlink attacks

2008-09-01 Thread Andreas Putzo
Package: nfdump Version: 1.5.7-4 Severity: grave Tags: security Hi, nfdump in its default installation starts nfcapd as a daemon that creates a file in /var/tmp/nfcapd.current. as well as /var/tmp/nfcapd.. These files are vulnerable to symlink attacks which is especially worse because nfcapd run