Advisories ยป MGASA-2013-0254

Updated perl-Proc-ProcessTable packages fix CVE-2011-4363

Publication date: 22 Aug 2013
Type: security
Affected Mageia releases : 2 , 3
CVE: CVE-2011-4363

Description

Updated perl-Proc-ProcessTable package fixes security vulnerability:

ProcessTable.pm in the Proc::ProcessTable module 0.45 for Perl, when TTY
information caching is enabled, allows local users to overwrite arbitrary
files via a symlink attack on /tmp/TTYDEVS (CVE-2011-4363).
                

References

SRPMS

3/core

2/core