ALT-PU-2020-3208-1
Closed vulnerabilities
Published: 2008-11-05
Modified: 2017-08-08
Modified: 2017-08-08
CVE-2008-4935
asciiview in aview 1.3.0 allows local users to overwrite arbitrary files via a symlink attack on a /tmp/aview#####.pgm temporary file.
References:
- http://dev.gentoo.org/~rbu/security/debiantemp/aview
- http://bugs.debian.org/496422
- [oss-security] 20081030 CVE requests: tempfile issues for aview, mgetty, openoffice, crossfire
- https://bugs.gentoo.org/show_bug.cgi?id=235770
- https://bugs.gentoo.org/235808
- 33139
- 30885
- GLSA-200812-14
- aview-asciiview-symlink(44837)