The perform_file_save function in GNOME Workstation Command Center (gwcc) 0.9.6 and earlier allows local users to create and overwrite arbitrary files via a symlink attack on the gwcc_out.txt temporary file.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Gnome_workstation_command_center | Brent_ely | * | 0.9.6 (including) |
Gnome_workstation_command_center | Brent_ely | 0.9.8 (including) | 0.9.8 (including) |