Bug#294352: CAN-2004-2473 symlink vulnerability

2005-08-22 Thread Stefan Fritsch
I didn't notice, but now I found the reasoning: http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=282656;msg=7;archive=yes Stefan -- To UNSUBSCRIBE, email to [EMAIL PROTECTED] with a subject of "unsubscribe". Trouble? Contact [EMAIL PROTECTED]

Bug#294352: CAN-2004-2473 symlink vulnerability

2005-08-21 Thread Joey Hess
Stefan Fritsch wrote: > If wmFrog is ever packaged vor Debian, care should be taken that > CAN-2004-2473 is fixed: > "wmFrog weather monitor 0.1.6 allows local users to overwrite > arbitrary files via a symlink attack on temporary files." > > See http://xforce.iss.net/xforce/xfdb/18232 Actually

Bug#294352: CAN-2004-2473 symlink vulnerability

2005-08-21 Thread Stefan Fritsch
If wmFrog is ever packaged vor Debian, care should be taken that CAN-2004-2473 is fixed: "wmFrog weather monitor 0.1.6 allows local users to overwrite arbitrary files via a symlink attack on temporary files." See http://xforce.iss.net/xforce/xfdb/18232 -- To UNSUBSCRIBE, email to [EMAIL PROTEC