You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
zanchey
changed the title
psub and funced don't protect tempfiles (CVE-2014-2906)
psub and funced don't protect tempfiles (CVE-2014-2906 and CVE-2014-3856)
Sep 26, 2014
psub
andfunced
both create temporary files using reasonably predictable names and are vulnerable to a race condition.For
funced
, the file is sourced directly, allowing privilege escalation (CVE-2014-3856).For
psub
, the file is given as an argument to other programs, allowing incorrect input to these programs (CVE-2014-2906).The text was updated successfully, but these errors were encountered: