The lvmcreate_initrd script in the lvm package in Trustix Secure Linux 1.5 through 2.1, and possibly other operating systems, allows local users to overwrite files via a symlink attack on temporary files.
| Software | From | Fixed in |
|---|---|---|
| lvm / logical_volume_management_utilities | 1.0.8 | 1.0.8.x |
| lvm / logical_volume_management_utilities | 1.0.4 | 1.0.4.x |
| lvm / logical_volume_management_utilities | 1.0.1 | 1.0.1.x |
| lvm / logical_volume_management_utilities | 1.0.7 | 1.0.7.x |
| gentoo / linux | - | - |