Title : Fedora Security Update Fixes Emacspeak Temporary File Vulnerability VUPEN ID : VUPEN/ADV-2008-2722 CVE ID : CVE-2008-4191
Rated as : Low Risk
Remotely Exploitable : No Locally Exploitable : Yes Release Date : 2008-10-06
Technical Description
A vulnerability has been identified in Fedora, which could be exploited by local attackers to bypass security restrictions. This issue is caused by an error in Emacspeak when handling a temporary directory via the "extract-table.pl" script, which could allow malicious users to conduct symlink attacks and overwrite arbitrary files with the privileges of the user invoking the vulnerable application.