Shorewall Insecure Temporary File Handling Symbolic Link Vulnerability

Solution:
The vendor has provided fixes for this issue.

Mandrake has released an advisory (MDKSA-2004:080) and fixes to address this issue. Please see the referenced advisory for further details regarding obtaining and applying appropriate fixes.

Gentoo has released an advisory (GLSA 200407-07) to address this issue. Please see the referenced advisory for more information. Gentoo users may carry out the following commands to update their computers:

emerge sync
emerge -pv ">=net-firewall/shorewall-1.4.10f"
emerge ">=net-firewall/shorewall-1.4.10f"


Shorewall Shorewall 1.3.14

Shorewall Shorewall 1.3.7 c

Shorewall Shorewall 1.4

Shorewall Shorewall 1.4.1

Shorewall Shorewall 1.4.10

Shorewall Shorewall 1.4.2

Shorewall Shorewall 1.4.3 a

Shorewall Shorewall 1.4.3

Shorewall Shorewall 1.4.4

Shorewall Shorewall 1.4.5

Shorewall Shorewall 1.4.6

Shorewall Shorewall 1.4.7

Shorewall Shorewall 1.4.8

Shorewall Shorewall 1.4.9

Shorewall Shorewall 2.0

Shorewall Shorewall 2.0.1

Shorewall Shorewall 2.0.2

Shorewall Shorewall 2.0.3


 

Privacy Statement
Copyright 2010, SecurityFocus