USN-208-1: graphviz vulnerability
17 October 2005
graphviz vulnerability
Releases
Details
Javier Fernández-Sanguino Peña discovered that the "dotty" tool
created and used temporary files in an insecure way. A local attacker
could exploit this with a symlink attack to create or overwrite
arbitrary files with the privileges of the user running dotty.
Update instructions
The problem can be corrected by updating your system to the following package versions:
Ubuntu 5.04
-
graphviz
-
In general, a standard system update will make all the necessary changes.