Back to search
CVE-2007-4631
Published: Aug 31, 2007
Modified: Aug 7, 2024
PUBLISHED
Description
The DataLoader::doStart function in dataloader.cpp in QGit 1.5.6 and other versions up to 2pre1 allows local users to overwrite arbitrary files and execute arbitrary code via a symlink attack on temporary files with predictable filenames.
| Vendor | Product | Versions |
|---|---|---|
n/a | n/a | affected n/a |
References
https://bugzilla.redhat.com/show_bug.cgi?id=268381
x_refsource_MISC
http://sourceforge.net/project/shownotes.php?release_id=538002
x_refsource_CONFIRM
26745
third-party-advisory
x_refsource_SECUNIA
GLSA-200710-05
vendor-advisory
x_refsource_GENTOO
ADV-2007-3107
vdb-entry
x_refsource_VUPEN
26738
third-party-advisory
x_refsource_SECUNIA
27098
third-party-advisory
x_refsource_SECUNIA
FEDORA-2007-2108
vendor-advisory
x_refsource_FEDORA
qgit-dataloader-symlink(36503)
vdb-entry
x_refsource_XF
25618
vdb-entry
x_refsource_BID
http://bugs.gentoo.org/show_bug.cgi?id=190697
x_refsource_CONFIRM
Security Training
Train your team to recognize and prevent security threats with our comprehensive security awareness program.
Start TrainingVulnerability Scanning
Discover vulnerabilities in your applications and infrastructure before attackers do.
Scan Now