Bug#508940: CVE-2008-5379: Symlink attack

2008-12-19 Thread Gunnar Wolf
tag 508940 + patch thanks Hi, I am attaching a patch for this bug. Please note I have _not_ tested the patch, only quickly implemented it. This patch _does_ change the program's behaviour, although in the least intrusive way possible. Instead of downloading the file to work on to /tmp,

Bug#508940: CVE-2008-5379: Symlink attack

2008-12-16 Thread Steffen Joeris
Package: netdisco-mibs-installer Severity: grave Tags: security Justification: user security hole Hi, the following CVE (Common Vulnerabilities Exposures) id was published for netdisco-mibs-installer. CVE-2008-5379[0]: | netdisco-mibs-installer 1.0 allows local users to overwrite arbitrary |