3.3
CVSSv2

CVE-2012-3378

Published: 31/08/2012 Updated: 05/09/2012
CVSS v2 Base Score: 3.3 | Impact Score: 4.9 | Exploitability Score: 3.4
VMScore: 294
Vector: AV:L/AC:M/Au:N/C:N/I:P/A:P

Vulnerability Summary

The register_application function in atk-adaptor/bridge.c in GNOME at-spi2-atk 2.5.2 does not seed the random number generator and generates predictable temporary file names, which makes it easier for local users to create or truncate files via a symlink attack on a temporary socket file in /tmp/at-spi2.

Vulnerable Product Search on Vulmon Subscribe to Product

gnome at-spi2-atk 2.5.2

Vendor Advisories

Debian Bug report logs - #678026 libatk-adaptor: CVE-2012-3378: insecure tempdir handling Package: libatk-adaptor; Maintainer for libatk-adaptor is Debian Accessibility Team <pkg-a11y-devel@listsaliothdebianorg>; Source for libatk-adaptor is src:at-spi2-atk (PTS, buildd, popcon) Reported by: Julien Cristau <jcristau@de ...