Fedora: 2: im-sdk Insecure temporary file vulnerability
Summary
IIIMF is a next generation multilingual Unicode input method framework,
which is a replacement of existing input method frameworks such as XIM.
This IIIMF implementation includes Language Engines for various Asian
languages allowing one to switch between inputting complex charactersin a number of different languages in supported applications.
Update Information:
The im-switch that is included in the Fedora Core iiimf-x package
has been fixed to take appropriate precautions when generating
temporary files.
* Mon Jul 05 2004 Jens Petersen <petersen@redhat.com> - 1:11.4-46.1.svn1587
- fix im-switch to use mktemp to generate temp file securely
(Tatsuo Sekine, 126940)
This update can be downloaded from:
24099c1a908d3cf91fd3fcd0cf819702 SRPMS/im-sdk-11.4-46.1.svn1587.src.rpm 220fff6d7c7d6ae6c6959e54aadb6a97 x86_64/iiimf-csconv-11.4-46.1.svn1587.x86_64.rpm d00917c7cbcd45b37e035149a97760d8 x86_64/iiimf-protocol-lib-11.4-46.1.svn1587.x86_64.rpm a0195ae081724d55a5d77c3330ff31f9 x86_64/iiimf-protocol-lib-devel-11.4-46.1.svn1587.x86_64.rpm 105b29382ca9548cf5db880c9456d981 x86_64/iiimf-client-lib-11.4-46.1.svn1587.x86_64.rpm 93810869492d32f133f879b7a5d47f0e x86_64/iiimf-client-lib-devel-11.4-46.1.svn1587.x86_64.rpm 5911c376fc0010fac972ad6997d562c8 x86_64/iiimf-server-11.4-46.1.svn1587.x86_64.rpm 50b5765f7333fd9cd3446de2ef1467f7 x86_64/iii...
Read the Full AdvisoryChange Log
References
Fedora Update Notification FEDORA-2004-208 2004-07-08 Product : Fedora Core 2 Name : im-sdk Version : 11.4 Release : 46.1.svn1587 Summary : IIIMF multilingual Unicode input method framework Description : IIIMF is a next generation multilingual Unicode input method framework, which is a replacement of existing input method frameworks such as XIM. This IIIMF implementation includes Language Engines for various Asian languages allowing one to switch between inputting complex charactersin a number of different languages in supported applications.