|
|
Info |
Last Modified |
| 6 months ago |
|
|
|
|
Description |
Mandrake Linux contains a flaw that may allow a malicious user to perform a symlink attack. The issue is due to insecure tempotary file creation in the "/tmp" directory by the ksymoops-gznm script. It is possible that the flaw may allow a local attacker to delete arbitrary file on the system with a symlink pointing to an arbitrary file, resulting in a loss of integrity.
|
|
Classification |
Location:
Local Access Required
Attack Type:
Race Condition
Impact:
Loss of Integrity
Exploit:
Exploit Available
Disclosure:
OSVDB Verified
|
|
Solution |
Currently, there are no known workarounds or upgrades to correct this issue. However, MandrakeSoft has released a patch to address this vulnerability.
|
|
Products |
|
Corporate Server
 |
2.1 |
Mandrakelinux
 |
10.0 |
9.1 |
9.2 |
|
|
|
|
|
BlogsProvided by Technorati
|
None found at this time
|
|
|