The tempname_ensure function in lib/routines.h in a2ps 4.14 and previous versions, as used by the spy_user function and possibly other functions, allows local users to modify arbitrary files via a symlink attack on a temporary file.
Vulnerable Product | Search on Vulmon | Subscribe to Product |
---|---|---|
gnu a2ps 4.10.4 |
||
gnu a2ps |
||
gnu a2ps 4.13b |
||
gnu a2ps 4.13 |
||
gnu a2ps 4.10.3 |
||
gnu a2ps 4.12 |