Required CVE Record Information
Description
liguidsoap.py in liguidsoap 0.3.8.1+2 allows local users to overwrite arbitrary files via a symlink attack on (1) /tmp/liguidsoap.liq, (2) /tmp/lig.#####.log, and (3) /tmp/emission.ogg temporary files.
References 7 Total
- openwall.com: [oss-security] 20081030 CVE requests: tempfile issues for aview, mgetty, openoffice, crossfire mailing-list
- https://bugs.gentoo.org/show_bug.cgi?id=235770
- http://dev.gentoo.org/~rbu/security/debiantemp/liguidsoap
- securityfocus.com: 30912 vdb-entry
- exchange.xforce.ibmcloud.com: liquidsoap-liquidsoap-symlink(44827) vdb-entry
- http://uvw.ru/report.lenny.txt
- http://bugs.debian.org/496360
Updated:
This container includes required additional information provided by the CVE Program for this vulnerability.
References 7 Total
- openwall.com: [oss-security] 20081030 CVE requests: tempfile issues for aview, mgetty, openoffice, crossfire mailing-listx_transferred
- https://bugs.gentoo.org/show_bug.cgi?id=235770 x_transferred
- http://dev.gentoo.org/~rbu/security/debiantemp/liguidsoap x_transferred
- securityfocus.com: 30912 vdb-entryx_transferred
- exchange.xforce.ibmcloud.com: liquidsoap-liquidsoap-symlink(44827) vdb-entryx_transferred
- http://uvw.ru/report.lenny.txt x_transferred
- http://bugs.debian.org/496360 x_transferred