1
0
mirror of https://git.FreeBSD.org/ports.git synced 2025-01-23 09:10:43 +00:00

Document heartbeat -- insecure temporary file creation vulnerability.

This commit is contained in:
Remko Lodder 2006-02-16 09:08:03 +00:00
parent 8217045be7
commit 16ea24ccb4
Notes: svn2git 2021-03-31 03:12:20 +00:00
svn path=/head/; revision=156145

View File

@ -34,6 +34,34 @@ Note: Please add new entries to the beginning of this file.
-->
<vuxml xmlns="http://www.vuxml.org/apps/vuxml-1">
<vuln vid="f6447303-9ec9-11da-b410-000e0c2e438a">
<topic>heartbeat -- insecure temporary file creation vulnerability</topic>
<affects>
<package>
<name>heartbeat</name>
<range><ge>0</ge></range>
</package>
</affects>
<description>
<body xmlns="http://www.w3.org/1999/xhtml">
<p>Eric Romang reports a temporary file creation vulnerability
within heartbeat. The vulnerability is caused by hardcoded
temporary file usage. This can cause an attacker to create
an arbitrary symlink causing the application to overwrite the
symlinked file with the permissions of the user executing the
application.</p>
</body>
</description>
<references>
<cvename>CAN-2005-2231</cvename>
<url>http://www.zataz.net/adviso/heartbeat-06272005.txt</url>
</references>
<dates>
<discovery>2005-07-12</discovery>
<entry>2006-02-16</entry>
</dates>
</vuln>
<vuln vid="432bf98d-9e25-11da-b410-000e0c2e438a">
<topic>kpdf -- heap based buffer overflow</topic>
<affects>