Gentoo: GLSA-200502-01: FireHOL: Insecure temporary file creation
Summary
Gentoo Linux Security Advisory GLSA 200502-01
https://security.gentoo.org/
Severity: Normal
Title: FireHOL: Insecure temporary file creation
Date: February 01, 2005
Bugs: #79330
ID: 200502-01
Synopsis
=======
FireHOL is vulnerable to symlink attacks, potentially allowing a local
user to overwrite arbitrary files.
Background
=========
FireHOL is an iptables rules generator.
Affected packages
================
-------------------------------------------------------------------
Package / Vulnerable / Unaffected
-------------------------------------------------------------------
1 net-firewall/firehol < 1.224 >= 1.224
==========
FireHOL insecurely creates temporary files with predictable names.
Impact
=====
A local attacker could create malicious symbolic links to arbitrary
system files. When FireHOL is executed...
Resolution
References
Availability
Concerns
Background