Bug#508942: CVE-2008-5378: possible symlink attacks

2008-12-22 Thread Andreas Tille
Hi, when I started manitaining arb I noticed that the program might crash under some seldom occurrences. To enable the users to start cleanly another instance I enhanced the scripts provided by upstream which basically parse a file containing the PIDs of the main arb processes. These files are

Bug#508942: CVE-2008-5378: possible symlink attacks

2008-12-16 Thread Steffen Joeris
Package: arb Severity: important Tags: security Hi, the following CVE (Common Vulnerabilities Exposures) id was published for arb. CVE-2008-5378[0]: | arb-kill in arb 0.0.20071207.1 allows local users to overwrite | arbitrary files via a symlink attack on a /tmp/arb_pids_*_* temporary | file.