tmp file overwrites

Bug #86906 reported by Kees Cook
6
Affects Status Importance Assigned to Milestone
gnucash (Ubuntu)
Fix Released
Undecided
Unassigned

Bug Description

Binary package hint: gnucash

Temp file overwrite vulnerability, fixed in 2.0.5.

CVE References

Revision history for this message
magilus (magilus) wrote :

Easiest way to fix that is to sync a UVF exception for 2.0.5 from Debian.

Changed in gnucash:
assignee: nobody → pirast
status: Unconfirmed → Confirmed
Revision history for this message
magilus (magilus) wrote :
Revision history for this message
magilus (magilus) wrote :
Revision history for this message
magilus (magilus) wrote :

Compiling of 2.0.5 fails for me although I applied the Ubuntu changes. I'd be happy if anyone else could fix this bug.

Changed in gnucash:
assignee: pirast → nobody
Revision history for this message
andi5 (andi5) wrote :

gnucash 2.0.5-1ubuntu1 has been uploaded.

Changed in gnucash:
status: Confirmed → Fix Released
To post a comment you must log in.
This report contains Public information  
Everyone can see this information.

Other bug subscribers

Remote bug watches

Bug watches keep track of this bug in other bug trackers.