| OSVDB ID | Disclosure Date | Title |
|
56054
Description:
The GNU Stream Editor (sed) contains a flaw that may allow a local attacker to gain access to sensitive information or manipulate arbitrary user's date. The issue is due to utils.c (ck_mkstemp) not setting a restrictive umask on temporary files.
|
2009-06-28
|
GNU Stream Editor (sed) utils.c (ck_mkstemp) Temporary File umask Weakness
|
|
6509
Description:
(Description Provided by CVE) : GNU tar 1.13.19 and other versions before 1.13.25 allows remote attackers to overwrite arbitrary files via a symlink attack, as the result of a modification that effectively disabled the security check.
|
2001-07-02
|
GNU tar Arbitrary File Overwrite
|
|
8967
Description:
(Description Provided by CVE) : Directory traversal vulnerability in GNU tar 1.13.19 and earlier allows local users to overwrite arbitrary files during archive extraction via a tar file whose filenames contain a .. (dot dot).
|
2001-07-02
|
GNU tar Double Dot Archive Extraction Arbitrary File Overwrite
|
|
18704
Description:
(Description Provided by CVE) : Tar 1.15.1 does not properly warn the user when extracting setuid or setgid files, which may allow local users or remote attackers to gain privileges.
|
2005-08-04
|
GNU tar Extracted File Permission Warning Weakness
|
|
9063
Description:
(Description Provided by CVE) : Directory traversal vulnerability in GNU tar 1.13.19 through 1.13.25, and possibly later versions, allows attackers to overwrite arbitrary files during archive extraction via a (1) "/.." or (2) "./.." string, which removes the leading slash but leaves the "..", a variant of CVE-2001-1267.
|
2001-07-02
|
GNU tar Extraction Arbitrary File Overwrite
|
|
30721
Description:
(Description Provided by CVE) : GNU tar 1.16 and 1.15.1, and possibly other versions, allows user-assisted attackers to overwrite arbitrary files via a tar file that contains a GNUTYPE_NAMES record with a symbolic link, which is not properly handled by the extract_archive function in extract.c and extract_mangle function in mangle.c, a variant of CVE-2002-1216.
|
2006-11-21
|
GNU tar GNUTYPES_NAMES Record Type Traversal Arbitrary File Overwrite
|
|
23371
Description:
A remote overflow exists in GNU Tar. GNU Tar fails to properly handle PAX extended headers resulting in a buffer overflow. With a specially crafted .tar archive, an attacker can cause arbitrary command execution when the victim lists the tar contents or extracts the archive.
|
2006-02-22
|
GNU tar PAX Extended Headers Handling Overflow
|
|
62950
Description:
GNU tar is prone to an overflow condition. The program fails to properly sanitize user-supplied input resulting in a heap overflow. With a specially crafted response or file, a remote attacker can potentially cause arbitrary code execution.
|
2010-03-10
|
GNU tar rmt Client lib/rtapelib.c rmt_read__ Function Remote Overflow
|
|
42149
Description:
(Description Provided by CVE) : Buffer overflow in the safer_name_suffix function in GNU tar has unspecified attack vectors and impact, resulting in a "crashing stack."
|
2007-09-06
|
GNU tar safer_name_suffix Function Unspecified Overflow
|
|
38183
Description:
(Description Provided by CVE) : Directory traversal vulnerability in the contains_dot_dot function in src/names.c in GNU tar allows user-assisted remote attackers to overwrite arbitrary files via certain //.. (slash slash dot dot) sequences in directory symlinks in a TAR archive.
|
2007-08-13
|
GNU tar src/names.c contains_dot_dot Function Traversal Arbitrary File Overwrite
|
|
19409
Description:
(Description Provided by CVE) : The sort_offline function for texindex in texinfo 4.8 and earlier allows local users to overwrite arbitrary files via a symlink attack on temporary files.
|
2005-09-14
|
GNU Texinfo textindex.c Symlink Arbitrary File Overwrite
|
|
68810
Description:
(Description Provided by CVE) : The (1) texmacs and (2) tm_mupad_help scripts in TeXmacs 1.0.7.4 place a zero-length directory name in the LD_LIBRARY_PATH, which allows local users to gain privileges via a Trojan horse shared library in the current working directory.
|
2010-09-28
|
GNU TeXmacs Multiple Scripts LD_LIBRARY_PATH Zero-length Directory Name Path Subversion Local Privilege Escalation
|
|
3950
Description:
The GNU Transport Layer Security Library contains a flaw that may allow a malicious user to disclose sensitive information about the information protected by the security features of the GNU Transport Layer Security Library. It is currently undocumented as to what exact conditions must be met to cause this condition. It is possible that the flaw may allow and attackers the ability to decrypted protected data resulting in a loss of information confidentiality.
|
2003-03-04
|
GNU TLS Library Information Leakage
|
|
74393
Description:
(Description Provided by CVE) : The (1) configure and (2) config.guess scripts in GNU troff (aka groff) 1.20.1 on Openwall GNU/*/Linux (aka Owl) improperly create temporary files upon a failure of the mktemp function, which makes it easier for local users to overwrite arbitrary files via a symlink attack on a temporary file.
|
2009-08-14
|
GNU troff config.guess mktemp Function Weakness Temporary File Symlink Arbitrary File Overwrite
|
|
74389
Description:
(Description Provided by CVE) : The (1) config.guess, (2) contrib/groffer/perl/groffer.pl, and (3) contrib/groffer/perl/roff2.pl scripts in GNU troff (aka groff) 1.21 and earlier use an insufficient number of X characters in the template argument to the tempfile function, which makes it easier for local users to overwrite arbitrary files via a symlink attack on a temporary file, a different vulnerability than CVE-2004-0969.
|
2009-08-14
|
GNU troff config.guess tempfile Function template Argument X Character Temporary File Symlink Arbitrary File Overwrite
|
|
74392
Description:
(Description Provided by CVE) : The (1) configure and (2) config.guess scripts in GNU troff (aka groff) 1.20.1 on Openwall GNU/*/Linux (aka Owl) improperly create temporary files upon a failure of the mktemp function, which makes it easier for local users to overwrite arbitrary files via a symlink attack on a temporary file.
|
2009-08-14
|
GNU troff configure mktemp Function Weakness Temporary File Symlink Arbitrary File Overwrite
|
|
74386
Description:
(Description Provided by CVE) : The (1) contrib/eqn2graph/eqn2graph.sh, (2) contrib/grap2graph/grap2graph.sh, and (3) contrib/pic2graph/pic2graph.sh scripts in GNU troff (aka groff) 1.21 and earlier do not properly handle certain failed attempts to create temporary directories, which might allow local users to overwrite arbitrary files via a symlink attack on a file in a temporary directory, a different vulnerability than CVE-2004-1296.
|
2009-08-14
|
GNU troff contrib/eqn2graph/eqn2graph.sh Directory Creation Temporary File Symlink Arbitrary File Overwrite
|
|
74385
Description:
(Description Provided by CVE) : The (1) gendef.sh, (2) doc/fixinfo.sh, and (3) contrib/gdiffmk/tests/runtests.in scripts in GNU troff (aka groff) 1.21 and earlier allow local users to overwrite arbitrary files via a symlink attack on a gro#####.tmp or /tmp/##### temporary file.
|
2009-08-14
|
GNU troff contrib/gdiffmk/tests/runtests.in Multiple Temporary File Symlink Arbitrary File Overwrite
|
|
74387
Description:
(Description Provided by CVE) : The (1) contrib/eqn2graph/eqn2graph.sh, (2) contrib/grap2graph/grap2graph.sh, and (3) contrib/pic2graph/pic2graph.sh scripts in GNU troff (aka groff) 1.21 and earlier do not properly handle certain failed attempts to create temporary directories, which might allow local users to overwrite arbitrary files via a symlink attack on a file in a temporary directory, a different vulnerability than CVE-2004-1296.
|
2009-08-14
|
GNU troff contrib/grap2graph/grap2graph.sh Directory Creation Temporary File Symlink Arbitrary File Overwrite
|
|
74390
Description:
(Description Provided by CVE) : The (1) config.guess, (2) contrib/groffer/perl/groffer.pl, and (3) contrib/groffer/perl/roff2.pl scripts in GNU troff (aka groff) 1.21 and earlier use an insufficient number of X characters in the template argument to the tempfile function, which makes it easier for local users to overwrite arbitrary files via a symlink attack on a temporary file, a different vulnerability than CVE-2004-0969.
|
2009-08-14
|
GNU troff contrib/groffer/perl/groffer.pl tempfile Function template Argument X Character Temporary File Symlink Arbitrary File Overwrite
|
|
74391
Description:
(Description Provided by CVE) : The (1) config.guess, (2) contrib/groffer/perl/groffer.pl, and (3) contrib/groffer/perl/roff2.pl scripts in GNU troff (aka groff) 1.21 and earlier use an insufficient number of X characters in the template argument to the tempfile function, which makes it easier for local users to overwrite arbitrary files via a symlink attack on a temporary file, a different vulnerability than CVE-2004-0969.
|
2009-08-14
|
GNU troff contrib/groffer/perl/roff2.pl tempfile Function template Argument X Character Temporary File Symlink Arbitrary File Overwrite
|
|
74382
Description:
(Description Provided by CVE) : contrib/pdfmark/pdfroff.sh in GNU troff (aka groff) before 1.21 launches the Ghostscript program without the -dSAFER option, which allows remote attackers to create, overwrite, rename, or delete arbitrary files via a crafted document.
|
2009-07-24
|
GNU troff contrib/pdfmark/pdfroff.sh Ghostscript Launch Arbitrary File Manipulation
|
|
74388
Description:
(Description Provided by CVE) : The (1) contrib/eqn2graph/eqn2graph.sh, (2) contrib/grap2graph/grap2graph.sh, and (3) contrib/pic2graph/pic2graph.sh scripts in GNU troff (aka groff) 1.21 and earlier do not properly handle certain failed attempts to create temporary directories, which might allow local users to overwrite arbitrary files via a symlink attack on a file in a temporary directory, a different vulnerability than CVE-2004-1296.
|
2009-08-14
|
GNU troff contrib/pic2graph/pic2graph.sh Directory Creation Temporary File Symlink Arbitrary File Overwrite
|
|
74384
Description:
(Description Provided by CVE) : The (1) gendef.sh, (2) doc/fixinfo.sh, and (3) contrib/gdiffmk/tests/runtests.in scripts in GNU troff (aka groff) 1.21 and earlier allow local users to overwrite arbitrary files via a symlink attack on a gro#####.tmp or /tmp/##### temporary file.
|
2009-08-14
|
GNU troff doc/fixinfo.sh Multiple Temporary File Symlink Arbitrary File Overwrite
|
|
74383
Description:
(Description Provided by CVE) : The (1) gendef.sh, (2) doc/fixinfo.sh, and (3) contrib/gdiffmk/tests/runtests.in scripts in GNU troff (aka groff) 1.21 and earlier allow local users to overwrite arbitrary files via a symlink attack on a gro#####.tmp or /tmp/##### temporary file.
|
2009-08-14
|
GNU troff gendef.sh Multiple Temporary File Symlink Arbitrary File Overwrite
|
|
11130
Description:
(Description Provided by CVE) : The groffer script in the Groff package 1.18 and later versions, as used in Trustix Secure Linux 1.5 through 2.1, and possibly other operating systems, allows local users to overwrite files via a symlink attack on temporary files.
|
2004-09-30
|
GNU Troff groffer.sh Symlink Arbitrary File Manipulation
|
|
73111
Description:
(Description Provided by CVE) : contrib/pdfmark/pdfroff.sh in GNU troff (aka groff) before 1.21 allows local users to overwrite arbitrary files via a symlink attack on a pdf#####.tmp temporary file.
|
2009-07-24
|
GNU Troff pdfroff Temporary File Symlink Arbitrary File Overwrite
|
|
1479
Description:
(Description Provided by CVE) : GNU userv 1.0.0 and earlier does not properly perform file descriptor swapping, which can corrupt the USERV_GROUPS and USERV_GIDS environmental variables and allow local users to bypass some access restrictions.
|
2000-07-26
|
GNU userv Environment Variable Corruption Restriction Bypass
|
|
6982
Description:
wget contains a flaw that may allow a remote malicious user to write arbitrary files to the system. The issue is triggered when an NLST response from the server contains directory path information. It is possible that the flaw may allow arbitrary files to be written resulting in a loss of integrity.
|
2002-12-10
|
GNU wget Arbitrary File Creation / Overwrite
|
|
12639
Description:
(Description Provided by CVE) : wget 1.8.x and 1.9.x allows a remote malicious web server to overwrite certain files via a redirection URL containing a ".." that resolves to the IP address of the malicious server, which bypasses wget's filtering for ".." sequences.
|
2004-12-09
|
GNU wget DNS Poisoning File Overwrite
|