MDKSA-2001:015
- Nom du paquet
- exmh
- Date
- 2001-01-26
- Advisory ID
- MDKSA-2001:015
- Affected versions
- CS1.0 i586 , 6.1 i586 , 6.0 i586 , 7.0 i586 , 7.1 i586 , 7.2 i586
Problem description
All versions of exmh prior to 2.3.1 use the /tmp directory for storing temporary files. This was done in an insecure manner as exmh did not check to ensure that nobody placed a symlink with the same name in /tmp in the meantime and thus was vulnerable to a symlink attack. This could lead to a malicious local user being able to overwrite any file writable by the user executing exmh. These updated versions of exmh now use /tmp/username unless TMPDIR or EXMHTMPDIR is set.
Updated packages
CS1.0 i586
a34c9cc91e5a5b365c7cdfe4565a29fd 1.0.1/RPMS/exmh-2.1.1-5.1mdk.noarch.rpm 58d6b7a0c0c95005c5f5d924d5edab19 1.0.1/SRPMS/exmh-2.1.1-5.1mdk.src.rpm
6.1 i586
2d5601696033fb25e51712f2d510467f 6.1/RPMS/exmh-2.0.3-8.1mdk.noarch.rpm 92ca9c194cc6114f75ba33041a425330 6.1/SRPMS/exmh-2.0.3-8.1mdk.src.rpm
6.0 i586
df41f52609427ea68a23cabec9e5ecdf 6.0/RPMS/exmh-2.0.2-8.1mdk.noarch.rpm 8a2a479d1ed9a982e97745d62cd22a31 6.0/SRPMS/exmh-2.0.2-8.1mdk.src.rpm
7.0 i586
236ee27fb0498b1cc3c696d5d81c321f 7.0/RPMS/exmh-2.1.1-5.1mdk.noarch.rpm 58d6b7a0c0c95005c5f5d924d5edab19 7.0/SRPMS/exmh-2.1.1-5.1mdk.src.rpm
7.1 i586
a34c9cc91e5a5b365c7cdfe4565a29fd 7.1/RPMS/exmh-2.1.1-5.1mdk.noarch.rpm 58d6b7a0c0c95005c5f5d924d5edab19 7.1/SRPMS/exmh-2.1.1-5.1mdk.src.rpm
7.2 i586
efdd5d3fecc72805d1099693a6dfc7cb 7.2/RPMS/exmh-2.2-4.1mdk.noarch.rpm 1ac6b56522683d758aeda0e2c14fb7b6 7.2/SRPMS/exmh-2.2-4.1mdk.src.rpm
