Symlink Attack Vulnerability in Gnash by Gnash Project
CVE-2010-4337
Currently unrated
What is CVE-2010-4337?
In Gnash version 0.8.8, the configuration script is susceptible to a symlink attack, allowing local users to overwrite arbitrary files. This vulnerability occurs due to insufficient checks on temporary files created during the configuration process, specifically the /tmp/gnash-configure-errors.$$ and similar files. Malicious users can exploit this flaw, leading to potential data loss or system compromise by redirecting these temporary file paths to unintended locations.