Red Hat Bugzilla – Bug 124396
CAN-2004-0422 flim temporary file vulnerability affects semi packages
Last modified: 2007-11-30 17:06:54 EST
According to Debian advisory DSA 500-1: Tatsuya Kinoshita discovered a vulnerability in flim, an emacs library for working with internet messages, where temporary files were created without taking appropriate precautions. This vulnerability could potentially be exploited by a local user to overwrite files with the privileges of the user running emacs. Issue is public but low risk. CAN-2004-0422 Affects: 2.1AS 2.1AW 2.1ES 2.1WS
An errata has been issued which should help the problem described in this bug report. This report is therefore being closed with a resolution of ERRATA. For more information on the solution and/or where to find the updated files, please follow the link below. You may reopen this bug report if the solution does not work for you. http://rhn.redhat.com/errata/RHSA-2004-344.html