First published: Mon Jan 07 2013(Updated: )
Michael Scherer reported that the fedora-business-cards script used /tmp/fedora-business-cards-buffer.svg as a temporary file, which could be used in symlink attacks to overwrite the contents of a file with write permissions to the person running fedora-business-cards.
Credit: secalert@redhat.com
Affected Software | Affected Version | How to fix |
---|---|---|
Fedora | =17 | |
Fedora | =18 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2013-0159 has a moderate severity rating, indicating potential risk for data integrity through symlink attacks.
To fix CVE-2013-0159, update to a patched version of Fedora that addresses the symlink vulnerability in the fedora-business-cards script.
CVE-2013-0159 affects Fedora versions 17 and 18.
CVE-2013-0159 is associated with symlink attacks that could result in unauthorized file overwriting.
The vulnerability CVE-2013-0159 was reported by Michael Scherer.