[<prev] [next>] [thread-next>] [month] [year] [list]
Date: Thu, 18 Sep 2008 15:28:02 +0200
From: Jan Lieskovsky <jlieskov@...hat.com>
To: coley@...re.org
Cc: oss-security@...ts.openwall.com
Subject: CVE Request (openswan, emacspeak, cman)
Hello Steve,
could you please assign a CVE ids for the following three
issues:
a, openswan: Insecure auxiliary /tmp file usage (symlink attack possible)
Affected file: /usr/libexec/ipsec/livetest
References: https://bugzilla.redhat.com/show_bug.cgi?id=460425
http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=496374
b, emacspeak: Insecure auxiliary /tmp file usage (symlink attack possible)
Affected file: /usr/share/emacs/site-lisp/emacspeak/etc/extract-table.pl
References: https://bugzilla.redhat.com/show_bug.cgi?id=460435
http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=496431
c, cman: Insecure auxiliary /tmp file usage (symlink attack possible)
Affected file: /sbin/fence_egenera
References: https://bugzilla.redhat.com/show_bug.cgi?id=460476
http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=496410
Thank you in advance
Kind regards
Jan iankko Lieskovsky
RH Security Response Team
Please check out the
Open Source Software Security Wiki, which is counterpart to this
mailing list.
Hosted by DataForce ISP -
Powered by Openwall GNU/*/Linux