Symlink Attack Vulnerability in Gnash by Gnash Project
CVE-2010-4337
Currently unrated
Summary
In Gnash version 0.8.8, the configuration script is susceptible to a symlink attack, allowing local users to overwrite arbitrary files. This vulnerability occurs due to insufficient checks on temporary files created during the configuration process, specifically the /tmp/gnash-configure-errors.$$ and similar files. Malicious users can exploit this flaw, leading to potential data loss or system compromise by redirecting these temporary file paths to unintended locations.
References
Timeline
Vulnerability published
Vulnerability Reserved