imake in NetBSD before 2.0.3, NetBSD-current before 12 September 2005, certain versions of X.Org, and certain versions of XFree86 allows local users to overwrite arbitrary files via a symlink attack on the temporary file for the file.0 target, which is used for a pre-formatted manual page.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Netbsd | Netbsd | 1.6 (including) | 1.6 (including) |
Netbsd | Netbsd | 1.6-beta (including) | 1.6-beta (including) |
Netbsd | Netbsd | 1.6.1 (including) | 1.6.1 (including) |
Netbsd | Netbsd | 1.6.2 (including) | 1.6.2 (including) |
Netbsd | Netbsd | 2.0 (including) | 2.0 (including) |
Netbsd | Netbsd | 2.0.1 (including) | 2.0.1 (including) |
Netbsd | Netbsd | 2.0.2 (including) | 2.0.2 (including) |