Title : Fedora Security Update Fixes Geda-gnetlist Insecure Temporary File VUPEN ID : VUPEN/ADV-2008-3204 CVE ID : CVE-2008-5148
Rated as : Low Risk
Remotely Exploitable : No Locally Exploitable : Yes Release Date : 2008-11-20
Technical Description
A vulnerability has been identified in Fedora, which could be exploited by local attackers to bypass security restrictions. This issue is caused by an error in the "sch2eaglepos.sh" script in geda-gnetlist when handling temporary files, which could allow malicious users to conduct symlink attacks and overwrite arbitrary files.