Index: vuln.xml =================================================================== RCS file: /home/pcvs/ports/security/vuxml/vuln.xml,v retrieving revision 1.1191 diff -u -r1.1191 vuln.xml --- vuln.xml 15 Oct 2006 11:31:33 -0000 1.1191 +++ vuln.xml 15 Oct 2006 16:00:03 -0000 @@ -34,6 +34,33 @@ --> + + tkdiff -- temporary file symlink privilege escalation + + + tkdiff + 4.1.1 + + + + +

Javier Fernández-Sanguino Peña reports a vulnerability in + tkdiff which allows local users to gain priveleges of the + user running tkdiff due to insecure temporary file creation.

+ +
+ + http://www.debian.org/security/2005/dsa-927 + CVE-2005-3343 + 16064 + http://secunia.com/advisories/18083 + + + 2005-12-20 + 2006-10-15 + +
+ vtiger -- multiple remote file inclusion vulnerabilities @@ -4554,7 +4581,7 @@ -

Javier Fernandez-Sanguino Pena reports two temporary file +

Javier Fernández-Sanguino Peña reports two temporary file vulnerability within f2c. The vulnerabilities are caused due to weak temporary file handling. An attacker could create an symbolic link, causing a local user running f2c