openvas-scanner before 2011-09-11 creates a temporary file insecurely when generating OVAL system characteristics document with the ovaldi integrated tool enabled. A local attacker could use this flaw to conduct symlink attacks to overwrite arbitrary files on the system.
The product attempts to access a file based on the filename, but it does not properly prevent that filename from identifying a link or shortcut that resolves to an unintended resource.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Openvas-scanner | Openvas | * | 2011-09-11 (excluding) |
Openvas-server | Ubuntu | lucid | * |
Openvas-server | Ubuntu | maverick | * |
Openvas-server | Ubuntu | natty | * |
Openvas-server | Ubuntu | oneiric | * |
Openvas-server | Ubuntu | precise | * |
Openvas-server | Ubuntu | quantal | * |
Openvas-server | Ubuntu | raring | * |
Openvas-server | Ubuntu | saucy | * |
Openvas-server | Ubuntu | trusty | * |
Openvas-server | Ubuntu | upstream | * |
Openvas-server | Ubuntu | utopic | * |