GNU Sharutils Unshar Local Insecure Temporary File Creation Vulnerability

The GNU Sharutils 'unshar' utility creates temporary files in an insecure manner. A design error allows a file to be insecurely opened or created and subsequently written to.

A local attacker may leverage this issue to corrupt arbitrary files with the privileges of an unsuspecting user that activates the affected application.


 

Privacy Statement
Copyright 2010, SecurityFocus