>> GnuCash Unspecified Script Insecure Local Temporary File Creation Vulnerability
Title : GnuCash Unspecified Script Insecure Local Temporary File Creation Vulnerability VUPEN ID : VUPEN/ADV-2007-0653 CVE ID : CVE-2007-0007
Rated as : Low Risk
Remotely Exploitable : No Locally Exploitable : Yes Release Date : 2007-02-20
Technical Description
A vulnerability has been identified in GnuCash, which may be exploited by malicious users to conduct symlink attacks. This issue is due to temporary files being created and manipulated insecurely, which could be exploited by local attackers to create or overwrite arbitrary files with the privileges of the user running a vulnerable application.