Fedora: Xboard predictable file-write exploit
Summary
Xboard is an X Window System based graphical chessboard which can be
used with the GNUchess and Crafty chess programs, with Internet Chess
Servers (ICSs), with chess via email, or with your own saved games.
Install the xboard package if you need a graphical chessboard.
XBoard 4.2.6 and older contains a script which writes to a file in
/tmp with a predictable filename. Malicious users could use this
vulnerability to force XBoard users to overwrite any file writable
by them.
- update to 4.2.7
c9ee7f4bfdc30da49d4e4e968baf4512 SRPMS/xboard-4.2.7-1.src.rpm
ed2216de0ce24bf9d18423e5eb94d734 i386/xboard-4.2.7-1.i386.rpm
c22f3442cbd928378ace8d4aaaf4681f i386/debug/xboard-debuginfo-4.2.7-1.i386.rpm
This update can also be installed with the Update Agent; you can
launch the Update Agent with the 'up2date' command.
Change Log
References