Advisories ยป MGASA-2013-0331

Updated pmake packages fix CVE-2011-1920

Publication date: 20 Nov 2013
Modification date: 20 Nov 2013
Type: security
Affected Mageia releases : 2 , 3
CVE: CVE-2011-1920

Description

Updated pmake package fixes security vulnerability:

The make include files in NetBSD before 1.6.2, as used in pmake 1.111 and
earlier, allow local users to overwrite arbitrary files via a symlink attack
on a /tmp/_depend##### temporary file, related to bsd.lib.mk and bsd.prog.mk
(CVE-2011-1920).
                

References

SRPMS

2/core

3/core