Follow @Openwall on Twitter for new release announcements and other news
[<prev] [next>] [thread-next>] [day] [month] [year] [list]
Date:  Thu, 20 Nov 2008 21:32:53 -0600
From:  Raphael Geissert <atomo64+debian@...il.com>
To: oss-security@...ts.openwall.com
Subject:  CVE id request: chm2pdf insecure temporary files usage

-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1

Hello,

Versions 0.9 and 0.9.1 of chm2pdf allow local users to overwrite arbitrary files
via a symlink attacks on /tmp/chm2pdf

More information at http://bugs.debian.org/501959

Could a CVE id be assigned please?

Thanks in advance.

Cheers,
- -- 
Raphael Geissert - Debian Maintainer
www.debian.org - get.debian.net

-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.4.9 (GNU/Linux)

iEYEARECAAYFAkkmK+YACgkQYy49rUbZzlrDlgCeOsa92d/XCpTjT0b9EikJwme0
C6oAoJhWLgQjNn0U/8BgI3dy/s5Q1Eom
=w0+u
-----END PGP SIGNATURE-----

Powered by blists - more mailing lists

Please check out the Open Source Software Security Wiki, which is counterpart to this mailing list.

Confused about mailing lists and their use? Read about mailing lists on Wikipedia and check out these guidelines on proper formatting of your messages.