First published: Thu Dec 23 2004(Updated: )
The xdvizilla script in tetex-bin 2.0.2 creates temporary files with predictable file names, which allows local users to overwrite arbitrary files via a symlink attack.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Debian teTeX-bin | =2.0.2 | |
Gentoo Linux |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2004-1336 is rated as a medium severity vulnerability.
To fix CVE-2004-1336, update the tetex-bin package to a version that does not create predictable temporary file names.
CVE-2004-1336 affects Debian teTeX-bin version 2.0.2 and certain installations of Gentoo Linux.
A symlink attack in CVE-2004-1336 allows local users to overwrite arbitrary files by manipulating predictable temporary file names.
CVE-2004-1336 can be exploited by local users who have access to the system.