Gentoo: lprng Symlink attack
Summary
- - --------------------------------------------------------------------- GENTOO LINUX SECURITY ANNOUNCEMENT 200306-04 - - ---------------------------------------------------------------------
- - ---------------------------------------------------------------------
psbanner in the LPRng package allows local users to overwrite arbitrary files via a symbolic link attack on the /tmp/before file.
SOLUTION
It is recommended that all Gentoo Linux users who are running net-print/lprng upgrade to lprng-3.8.12-r1 as follows
emerge sync emerge lprng emerge clean
- - --------------------------------------------------------------------- aliz@gentoo.org - GnuPG key is available at - - ---------------------------------------------------------------------
Resolution
References
Availability
Concerns
Background