Description
The (1) fixps (aka fixps.in) and (2) psmandup (aka psmandup.in) scripts in a2ps before 4.13 allow local users to overwrite arbitrary files via a symlink attack on temporary files.
Affected products
- gnu / a2ps4.13 – 4.13
- gnu / a2ps4.13b – 4.13b
- turbolinux / turbolinux_home
- turbolinux / turbolinux_server7.0 – 7.0
- turbolinux / turbolinux_server8.0 – 8.0
- turbolinux / turbolinux_workstation7.0 – 7.0
- turbolinux / turbolinux_workstation8.0 – 8.0
References
- MISChttp://www.gentoo.org/security/en/glsa/glsa-200501-02.xml
- MISChttp://www.securityfocus.com/bid/12109
- MISChttp://www.vuxml.org/freebsd/9168253c-5a6d-11d9-a9e7-0001020eed82.html
- MISChttp://www.securityfocus.com/bid/12108
- MISChttps://exchange.xforce.ibmcloud.com/vulnerabilities/18671
- MISChttps://exchange.xforce.ibmcloud.com/vulnerabilities/18672
- VENDOR_ADVISORYhttp://secunia.com/advisories/13641