Joined: 12 May 2004
|Posted: Wed Sep 09, 2009 10:26 pm Post subject: [ GLSA 200909-11 ] GCC-XML: Insecure temporary file usage
|Gentoo Linux Security Advisory
Title: GCC-XML: Insecure temporary file usage (GLSA 200909-11)
Date: September 09, 2009
An insecure temporary file usage has been reported in GCC-XML allowing for
GCC-XML is an XML output extension to the C++ front-end of GCC.
Vulnerable: < 0.9.0_pre20090516
Unaffected: >= 0.9.0_pre20090516
Architectures: All supported architectures
Dmitry E. Oboukhov reported that find_flags in GCC-XML does not handle
"/tmp/*.cxx" temporary files securely.
A local attacker could perform symlink attacks to overwrite arbitrary
files with the privileges of the user running the application.
There is no known workaround at this time.
All GCC-XML users should upgrade to the latest version:
|# emerge --sync
# emerge --ask --oneshot --verbose ">=dev-cpp/gccxml-0.9.0_pre20090516"
Last edited by GLSA on Sun Nov 22, 2009 4:29 am; edited 1 time in total