Symlink Attack Vulnerability in Gnash by Gnash Project
CVE-2010-4337

Currently unrated

Key Information:

Vendor
Gnu
Status
Vendor
CVE Published:
14 January 2011

Summary

In Gnash version 0.8.8, the configuration script is susceptible to a symlink attack, allowing local users to overwrite arbitrary files. This vulnerability occurs due to insufficient checks on temporary files created during the configuration process, specifically the /tmp/gnash-configure-errors.$$ and similar files. Malicious users can exploit this flaw, leading to potential data loss or system compromise by redirecting these temporary file paths to unintended locations.

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.