Secunia Security Advisory - A vulnerability in net-acct can be exploited by malicious, local users to perform certain actions on a vulnerable system with escalated privileges. The write_list() and dump_curr_list() functions create temporary files insecurely. This can be exploited via symlink attacks to overwrite or create arbitrary files with the privileges of a user executing net-acct. The vulnerability affects version 0.71 and prior.
886a83d82b6914e96b17e662ee2d78abGNU automake versions below 1.8.3 insecurely create temporary directories.
f9c55471d01e6d32e77da15025fdea64Versions below 1.5.2 of GNU's libtool have a symlink vulnerability that creates a temporary directory when a package using libtool is being compiled.
d766b2d1a4e7de15f711c5c120268916A vulnerability exists in the susewm package in SuSE Linux 8.2Pro where a symbolic link attack can escalate a user to root privileges. Workaround included.
b5bea3f6c03c7303baa376897fd1135cThe javarunt package distributed with SuSE Linux 7.3Pro is vulnerable to a local symbolic link attack that can achieve root privileges. Workaround included.
2fdb594b766cef38b741c1f7f39ed79c