oss-sec mailing list archives

[notification] txt2man unsafe use of tempoarary files


From: Salvatore Bonaccorso <carnil () debian org>
Date: Wed, 25 Sep 2013 22:43:06 +0200

Hi

This is a notification that CVE-2013-1444 was assigned to the
following issue[1] (affecting Debian and derivatives syncing from
Debian the txt2man package):

txt2man uses tempoary files in /tmp/ (specific /tmp/2222), Debian
applied a patch including:

echo $post > /tmp/2222

in txt2man. This reported by Patrick J Cherry.

References:

 [1] http://bugs.debian.org/724614

Regards,
Salvatore

Attachment: signature.asc
Description: Digital signature


Current thread: