1 results (0.003 seconds)

CVSS: 7.8EPSS: 0%CPEs: 19EXPL: 0

31 Jan 2008 — PatchLink Update client for Unix, as used by Novell ZENworks Patch Management Update Agent for Linux/Unix/Mac (LUM) 6.2094 through 6.4102 and other products, allows local users to (1) truncate arbitrary files via a symlink attack on the /tmp/patchlink.tmp file used by the logtrimmer script, and (2) execute arbitrary code via a symlink attack on the /tmp/plshutdown file used by the rebootTask script. El cliente PatchLink Update para Unix, tal y como es usado por Novell ZENworks Patch Management Update Agent ... • http://secunia.com/advisories/28657 • CWE-59: Improper Link Resolution Before File Access ('Link Following') •