OpenBSD VuXML: Documenting security issues in the OpenBSD Ports & Packages Collection

net-snmp -- fixproc insecure temporary file creation

Affected packages
net-snmp < 5.1.2p1

Details

VuXML ID 75ecb34c-cc7d-11d9-8e94-00065bd5b0b6
Discovery 2005-05-23
Entry 2005-05-25

A malicious local attacker could exploit a race condition to change the content of the temporary files before they are executed by fixproc, possibly leading to the execution of arbitrary code. A local attacker could also create symbolic links in the temporary files directory, pointing to a valid file somewhere on the filesystem. When fixproc is executed, this would result in the file being overwritten.

References

URL http://www.gentoo.org/security/en/glsa/glsa-200505-18.xml