|
|
Info |
Last Modified |
| about 1 year ago |
|
|
|
|
|
Description |
Tux Paint contains a flaw that may allow a malicious local user to overwrite or create arbitrary files on the system. The issue is due to the tuxpaint-import.sh script creating temporary files insecurely. It is possible for a user to use a symlink style attack to manipulate arbitrary files, resulting in a loss of integrity.
|
|
Classification |
Location:
Local Access Required
Attack Type:
Race Condition
Impact:
Loss of Integrity
Exploit:
Exploit Unknown
|
|
Solution |
Upgrade to version 0.9.15 or higher, as it has been reported to fix this vulnerability. An upgrade is required as there are no known workarounds. Ubuntu users may upgrade to version 1:0.9.14-2ubuntu0.1. Debian users may upgrade to version 0.9.14-2sarge0.
|
|
Products |
|
Tux Paint
 |
0.9.14 |
|
|
|
|
|
|
Credit |
- Javier Fernandez-Sanguino Pena - jfs
computer.org -
|
|
BlogsProvided by Technorati
|
None found at this time
|
|
|