Oval Definition:
oval:org.mitre.oval:def:7317
Revision Date
:
2014-06-23
Version
:
18
Title
:
DSA-1674 jailer -- insecure temp file generation
Description
:
Javier Fernandez-Sanguino Pena discovered that updatejail, a component of the chroot maintenance tool Jailer, creates a predictable temporary file name, which may lead to local denial of service through a symlink attack.
Family
:
unix
Class
:
patch
Status
:
ACCEPTED
Reference(s)
:
CVE-2008-5139
DSA-1674
Platform(s)
:
Debian GNU/Linux 4.0
Product(s)
:
jailer
Definition Synopsis
Debian GNU/Linux 4.0 is installed.
AND
Installed architecture is all
AND
jailer is earlier than 0.4-9+etch1
BACK