welcome.py in xdiagnose before 2.5.2ubuntu0.1 allows local users to overwrite arbitrary files via a symlink attack on a temporary file with a predictable name in /tmp.
The product attempts to access a file based on the filename, but it does not properly prevent that filename from identifying a link or shortcut that resolves to an unintended resource.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Xdiagnose | Bryce_harrington | * | 2.5 (including) |
Xdiagnose | Bryce_harrington | 0.2-0ubuntu2 (including) | 0.2-0ubuntu2 (including) |
Xdiagnose | Bryce_harrington | 1.6 (including) | 1.6 (including) |
Xdiagnose | Bryce_harrington | 1.6.1 (including) | 1.6.1 (including) |
Xdiagnose | Ubuntu | precise | * |
Xdiagnose | Ubuntu | upstream | * |