GForge Insecure Temporary File Creation Vulnerability

GForge creates temporary files in an insecure way.

An attacker with local access could potentially exploit this issue to perform symbolic-link attacks, overwriting arbitrary files in the context of the affected application. This may result in denial-of-service conditions; other attacks are also possible.


 

Privacy Statement
Copyright 2010, SecurityFocus