Gentoo: noweb insecure tmp file vulnerability
Summary
GENTOO LINUX SECURITY ANNOUNCEMENT 200306-16
quote from cve: "Multiple vulnerabilities in noweb 2.9 and earlier creates temporary files insecurely, which allows local users to overwrite arbitrary files via multiple vectors including the noroff script."
SOLUTION
It is recommended that all Gentoo Linux users who are running app-text/noweb upgrade to noweb-2.9-r3 as follows
emerge sync emerge noweb emerge clean
aliz@gentoo.org - GnuPG key is available at
Resolution
References
Availability
Concerns
Background