buttonpressed.sh in scanbuttond 0.2.3 allows local users to overwrite arbitrary files via a symlink attack on the (1) scan.pnm and (2) scan.jpg temporary files.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Fedora_core | Redhat | f7 (including) | f7 (including) |
Scanbuttond | Ubuntu | devel | * |
Scanbuttond | Ubuntu | edgy | * |
Scanbuttond | Ubuntu | feisty | * |
Scanbuttond | Ubuntu | gutsy | * |
Scanbuttond | Ubuntu | hardy | * |
Scanbuttond | Ubuntu | intrepid | * |