DescriptionMurray McAllister
2014-04-16 04:21:35 UTC
Jakub Wilk discovered that clang's scan-build utility insecurely handled temporary files. A local attacker could use this flaw to perform a symbolic link attack against users running the scan-build utility.
Original report: https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=744817
Comment 1Murray McAllister
2014-04-16 04:23:12 UTC
This issue affects the llvm package in Fedora and EPEL. python-llvmpy and mingw-llvm are not affected.
Comment 2Murray McAllister
2014-04-16 04:24:19 UTC
Created llvm tracking bugs for this issue:
Affects: fedora-all [bug 1088107]
Affects: epel-6 [bug 1088108]
Comment 3Murray McAllister
2014-04-16 04:28:04 UTC