The fn_show_postinst function in Gentoo webapp-config before 1.10-r14 allows local users to overwrite arbitrary files via a symlink attack on the postinst.txt temporary file.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Linux_webapp-config | Gentoo | 1.10-r14 (including) | 1.10-r14 (including) |