netdisco-mibs-installer 1.0 allows local users to overwrite arbitrary files via a symlink attack on the /tmp/netdisco-mibs-0.6.tar.gz temporary file, related to the (1) netdisco-mibs-install and (2) netdisco-mibs-download scripts.
The product attempts to access a file based on the filename, but it does not properly prevent that filename from identifying a link or shortcut that resolves to an unintended resource.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Netdisco_mibs_installer | Oliver_gorwits | 1.0 (including) | 1.0 (including) |
Netdisco-mibs-installer | Ubuntu | intrepid | * |
Netdisco-mibs-installer | Ubuntu | jaunty | * |
Netdisco-mibs-installer | Ubuntu | karmic | * |
Netdisco-mibs-installer | Ubuntu | upstream | * |