|
|
Info |
Last Modified |
| 10 months ago |
|
|
|
|
Description |
Gentoo mirrorselect contains a flaw that may allow a malicious user to overwrite arbitrary files using symlink attacks. The issue is triggered when mirrorselect is executed and it overwritten the file with the user running mirror select permissions. It is possible that the flaw may allow arbitrary files being overwritten resulting in a loss of integrity.
|
|
Classification |
Location:
Local Access Required
Attack Type:
Race Condition
Impact:
Loss of Integrity
Exploit:
Exploit Unknown
|
|
Solution |
Upgrade to version 0.89 or higher, as it has been reported to fix this vulnerability. An upgrade is required as there are no known workarounds.
|
|
Products |
|
app-portage/mirrorselect
 |
0.89 |
0.86 |
0.85 |
0.84 |
0.83 |
0.82 |
|
|
|
|
|
BlogsProvided by Technorati
|
None found at this time
|
|
|