CVE-2008-0525 (PatchLink Update) [Sitemap] - HeapOverflow Computer Security Community & Forums : Heap Overflow.com

PDA

View Full Version : CVE-2008-0525 (PatchLink Update)


Heap
01-02-08, 20:35
PatchLink Update client for Unix allows local users to (1) truncate arbitrary files via a symlink attack on the /tmp/patchlink.tmp file used by the logtrimmer script, and (2) execute arbitrary code via a symlink attack on the /tmp/plshutdown file used by the rebootTask script.

More... (http://nvd.nist.gov/nvd.cfm?cvename=CVE-2008-0525)