- - - ---------------------------------------------------------------------
GENTOO LINUX SECURITY ANNOUNCEMENT 200306-16
- - - ---------------------------------------------------------------------

          PACKAGE : noweb
          SUMMARY : insecure temporary file creations
             DATE : 2003-06-28 20:23 UTC
          EXPLOIT : local
VERSIONS AFFECTED : =noweb-2.9-r3
              CVE : CAN-2003-0381

- - - ---------------------------------------------------------------------

quote from cve:
"Multiple vulnerabilities in noweb 2.9 and earlier creates temporary 
files insecurely, which allows local users to overwrite arbitrary files 
via multiple vectors including the noroff script."

SOLUTION

It is recommended that all Gentoo Linux users who are running
app-text/noweb upgrade to noweb-2.9-r3 as follows

emerge sync
emerge noweb
emerge clean

- - - ---------------------------------------------------------------------
aliz@gentoo.org - GnuPG key is available at   
- - - ---------------------------------------------------------------------

Gentoo: noweb insecure tmp file vulnerability

Multiple vulnerabilities in noweb 2.9 and earlier creates temporary files insecurely, which allows local users to overwrite arbitrary files via multiple vectors including the norof...

Summary


GENTOO LINUX SECURITY ANNOUNCEMENT 200306-16


quote from cve: "Multiple vulnerabilities in noweb 2.9 and earlier creates temporary files insecurely, which allows local users to overwrite arbitrary files via multiple vectors including the noroff script."
SOLUTION
It is recommended that all Gentoo Linux users who are running app-text/noweb upgrade to noweb-2.9-r3 as follows
emerge sync emerge noweb emerge clean
aliz@gentoo.org - GnuPG key is available at

Resolution

References

Availability

Concerns

Severity
PACKAGE : noweb
SUMMARY : insecure temporary file creations
DATE : 2003-06-28 20:23 UTC
EXPLOIT : local
VERSIONS AFFECTED : =noweb-2.9-r3
CVE : CAN-2003-0381

Synopsis

Background

Affected Packages

Impact

Workaround

Related News