A flaw was fixed in perl-IPTables-Parse: (Miloslav Trmač) Fixed a vulnerability to not use predictable names for temporary files. This vulnerability would allow an attacker on a multi- user system to set up symlinks to overwrite any file the current user has write access to. If a user manually overrides the temporary file locations with the 'iptout' and 'ipterr' hash keys, it is recommended to not use predictable names either. CVE request: http://seclists.org/oss-sec/2015/q4/366 Upstream patch: https://github.com/mtrmac/IPTables-Parse/commit/b400b976d81140f6971132e94eb7657b5b0a2b87 External References: https://metacpan.org/source/MRASH/IPTables-Parse-1.6/Changes#L3
Created perl-IPTables-Parse tracking bugs for this issue: Affects: fedora-all [bug 1284923] Affects: epel-all [bug 1284924]
This is already #1267962, isn’t it?
(In reply to Miloslav Trmač from comment #2) > This is already #1267962, isn’t it? Bah, you're right. Sorry about that. Thanks for closing all of these. *** This bug has been marked as a duplicate of bug 1267962 ***