REDHAT-BUG-1088105: Low severity clang vulnerability
Jakub Wilk discovered that clang's scan-build utility insecurely handled temporary files. A local attacker could use this flaw to perform a symbolic link attack against users running the scan-build utility.
Original report: https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=744817
Affected Software
Event History
Frequently Asked Questions
What is the severity of REDHAT-BUG-1088105?
The severity of REDHAT-BUG-1088105 is considered medium due to the potential for local attackers to exploit the vulnerability.
How do I fix REDHAT-BUG-1088105?
To fix REDHAT-BUG-1088105, users should update to the latest patched version of clang that addresses the temporary file handling issue.
Who is affected by REDHAT-BUG-1088105?
Users running the scan-build utility in clang are affected by REDHAT-BUG-1088105.
Can REDHAT-BUG-1088105 be exploited remotely?
No, REDHAT-BUG-1088105 cannot be exploited remotely as it requires local access to the system.
What type of attack does REDHAT-BUG-1088105 enable?
REDHAT-BUG-1088105 enables a symbolic link attack which could be used by local attackers.