GNU A2PS fixps.in Script Insecure Temporary File Vulnerability

GNU a2ps is prone to a vulnerability that may allow malicious local users to corrupt files. This issue occurs because the 'fixps.in' script creates temporary files in an insecure manner, allowing symbolic-link attacks.

File corruption would occur in the context of the user running the script. It is not known if attackers could leverage this issue to elevate privileges.


 

Privacy Statement
Copyright 2010, SecurityFocus