|
Tiger Security Scanner contains a flaw that allows local attackers to overwrite arbitrary files or possibly gain root priveleges. The flaw is due to a lack of sanity checking on calls to temporary files created in /tmp that do not check for existing files with the same name. Such flaws can be taken advantage of with symlinks and arbitrary files can be overwritten or appended to.
|