USN-254-1: noweb vulnerability
22 February 2006
noweb vulnerability
Releases
Details
Javier Fernández-Sanguino Peña discovered that noweb scripts created
temporary files in an insecure way. This could allow a symlink attack
to create or overwrite arbitrary files with the privileges of the user
running noweb.
Update instructions
The problem can be corrected by updating your system to the following package versions:
Ubuntu 5.10
-
nowebm
-
Ubuntu 5.04
-
nowebm
-
Ubuntu 4.10
-
nowebm
-
In general, a standard system update will make all the necessary changes.