Back to search
CVE-2001-1593
Published: Apr 5, 2014
Modified: Aug 8, 2024
PUBLISHED
Description
The tempname_ensure function in lib/routines.h in a2ps 4.14 and earlier, as used by the spy_user function and possibly other functions, allows local users to modify arbitrary files via a symlink attack on a temporary file.
| Vendor | Product | Versions |
|---|---|---|
n/a | n/a | affected n/a |
References
https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=737385
x_refsource_CONFIRM
http://pkgs.fedoraproject.org/cgit/a2ps.git/plain/a2ps-4.13-security.patch
x_refsource_CONFIRM
https://bugzilla.redhat.com/show_bug.cgi?id=1060630
x_refsource_CONFIRM
[oss-security] 20140204 Re: CVE request: a2ps insecure temporary file use
mailing-list
x_refsource_MLIST
[oss-security] 20140205 Re: CVE request: a2ps insecure temporary file use
mailing-list
x_refsource_MLIST
DSA-2892
vendor-advisory
x_refsource_DEBIAN
[oss-security] 20140205 Re: CVE request: a2ps insecure temporary file use
mailing-list
x_refsource_MLIST
Security Training
Train your team to recognize and prevent security threats with our comprehensive security awareness program.
Start TrainingVulnerability Scanning
Discover vulnerabilities in your applications and infrastructure before attackers do.
Scan Now