First published: Wed Dec 31 2003(Updated: )
Xscreensaver before 4.15 creates temporary files insecurely in (1) driver/passwd-kerberos.c, (2) driver/xscreensaver-getimage-video, (3) driver/xscreensaver.kss.in, and the (4) vidwhacker and (5) webcollage screensavers, which allows local users to overwrite arbitrary files via a symlink attack.
Credit: secalert@redhat.com
Affected Software | Affected Version | How to fix |
---|---|---|
Xscreensaver Xscreensaver | =4.14_5 | |
Xscreensaver Xscreensaver | =4.14_4 | |
Xscreensaver Xscreensaver | =4.05_6 | |
Xscreensaver Xscreensaver | =4.10_15 | |
Xscreensaver Xscreensaver | =4.07_2 | |
Xscreensaver Xscreensaver | =4.08_29135cl | |
Xscreensaver Xscreensaver | =4.11_0 | |
Xscreensaver Xscreensaver | =4.14_0 | |
Xscreensaver Xscreensaver | =4.05_150 | |
Xscreensaver Xscreensaver | =4.05_6a | |
Xscreensaver Xscreensaver | =4.12_58 | |
Xscreensaver Xscreensaver | =4.10_4 | |
Xscreensaver Xscreensaver | =4.14_2 | |
Xscreensaver Xscreensaver | =4.05_5cl | |
Xscreensaver Xscreensaver | =4.10_6 | |
Xscreensaver Xscreensaver | =4.10_8 | |
Xscreensaver Xscreensaver | =4.09_0 | |
Xscreensaver Xscreensaver | =4.12_62 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.