FreeBSD VuXML: Documenting security issues in FreeBSD and the FreeBSD Ports Collection

CVE-2006-5072

This CVE name corresponds to:

Entered Topic
2006-10-05 mono -- "System.CodeDom.Compiler" Insecure Temporary Creation

The following information is adapted from the Common Vulnerabilities and Exposures (CVE) project. CVE and the CVE logo are trademarks of The MITRE Corporation. CVE content is Copyright 2005, The MITRE Corporation.

Details

Type Candidate
Name CVE-2006-5072
Phase Assigned(20060928)

Description

The System.CodeDom.Compiler classes in Novell Mono create temporary files with insecure permissions, which allows local users to overwrite arbitrary files or execute arbitrary code via a symlink attack.

References

Source Reference
FEDORA FEDORA-2007-068
GENTOO GLSA-200611-23
MANDRIVA MDKSA-2006:188
SUSE SUSE-SA:2006:073
UBUNTU USN-357-1
BID 20340
VUPEN ADV-2006-3911
SECUNIA 22237
SECUNIA 22277
SECUNIA 22614
SECUNIA 23154
SECUNIA 23213
SECUNIA 23776
XF mono-systemcodedomcompiler-symlink(29353)