First published: Fri May 06 2016(Updated: )
Cool Projects TarDiff allows local users to write to arbitrary files via a symlink attack on a pathname in a /tmp/tardiff-$$ temporary directory.
Credit: security@debian.org
Affected Software | Affected Version | How to fix |
---|---|---|
Debian GNU/Linux | =8.0 | |
TarDiff |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2015-0858 has a medium severity level due to its potential for local users to exploit symlink attacks.
To fix CVE-2015-0858, update the TarDiff package to the latest version that addresses the symlink vulnerability.
TarDiff versions prior to the patch that resolves CVE-2015-0858 are susceptible to this vulnerability.
CVE-2015-0858 cannot be exploited remotely as it requires local user privileges to execute the attack.
Yes, Debian Linux 8.0 is affected by CVE-2015-0858 due to the vulnerable version of TarDiff included.