Title : FreeBSD Security Update Fixes Texinfo Temporary File Creation Issue VUPEN ID : VUPEN/ADV-2006-0140 CVE ID : CVE-2005-3011
Rated as : Low Risk
Remotely Exploitable : No Locally Exploitable : Yes Release Date : 2006-01-11
Technical Description
FreeBSD has released security patches to address a vulnerability identified in GNU Texinfo. The problem is due to an error in the "textindex.c" file that creates temporary files insecurely, which may be exploited by local attackers to overwrite or create arbitrary files with the privileges of the user running the vulnerable application. For additional information, see : VUPEN/ADV-2005-1748