CVE-2012-3500
Publication date 3 September 2012
Last updated 24 July 2024
Ubuntu priority
scripts/annotate-output.sh in devscripts before 2.12.2, as used in rpmdevtools before 8.3, allows local users to modify arbitrary files via a symlink attack on the temporary (1) standard output or (2) standard error output file.
Status
Package | Ubuntu Release | Status |
---|---|---|
devscripts | 12.04 LTS precise |
Fixed 2.11.6ubuntu1.4
|
11.10 oneiric |
Fixed 2.11.1ubuntu3.2
|
|
11.04 natty |
Fixed 2.10.69ubuntu2.2
|
|
10.04 LTS lucid |
Fixed 2.10.61ubuntu5.3
|
|
8.04 LTS hardy | Ignored end of life |
Notes
Patch details
References
Related Ubuntu Security Notices (USN)
- USN-1593-1
- devscripts vulnerabilities
- 2 October 2012