First published: Mon Apr 14 2014(Updated: )
Jakub Wilk discovered that clang's scan-build utility insecurely handled temporary files. A local attacker could use this flaw to perform a symbolic link attack against users running the scan-build utility. Original report: <a href="https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=744817">https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=744817</a>
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
debian/llvm-toolchain-3.3 | ||
openSUSE openSUSE | =13.1 | |
Llvm Clang | <=3.5 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.