Total vulnerabilities in the database
The _rl_tropen function in util.c in GNU readline before 6.3 patch 3 allows local users to create or overwrite arbitrary files via a symlink attack on a /var/tmp/rltrace.[PID] file.
Software | From | Fixed in |
---|---|---|
mageia / mageia | 3.0 | 3.0.x |
mageia / mageia | 4.0 | 4.0.x |
gnu / readline | 4.2-a | 4.2-a.x |
gnu / readline | 6.2 | 6.2.x |
gnu / readline | - | 6.3.x |
gnu / readline | 5.1 | 5.1.x |
gnu / readline | 4.2 | 4.2.x |
gnu / readline | 2.2 | 2.2.x |
gnu / readline | 4.0 | 4.0.x |
gnu / readline | 5.0 | 5.0.x |
gnu / readline | 6.0 | 6.0.x |
gnu / readline | 2.1 | 2.1.x |
gnu / readline | 4.1 | 4.1.x |
gnu / readline | 4.3 | 4.3.x |
gnu / readline | 6.1 | 6.1.x |
gnu / readline | 5.2 | 5.2.x |
opensuse / opensuse | 12.3 | 12.3.x |
opensuse / opensuse | 13.1 | 13.1.x |
fedoraproject / fedora | 20 | 20.x |