Gentoo: 'eroaster' temporary file vulnerability
Summary
- - --------------------------------------------------------------------- GENTOO LINUX SECURITY ANNOUNCEMENT 200309-04 - - ---------------------------------------------------------------------
- - ---------------------------------------------------------------------
Previous eroaster versions allowwed local users to overwrite arbitrary files via a symlink attack on a temporary file that is used as a lockfile.
SOLUTION
It is recommended that all Gentoo Linux users who are running app-cdr/eroaster upgrade to eroaster-2.1.0-r2 as follows:
emerge sync emerge eroaster emerge clean
- - --------------------------------------------------------------------- aliz@gentoo.org - GnuPG key is available at - - ---------------------------------------------------------------------
Resolution
References
Availability
Concerns
Background