[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

INTERIM DECISION: ACCEPT 1 VEN-others candidates (Final 7/12)

I have made an Interim Decision to ACCEPT 1 of the candidates from
this cluster.  A Final Decision is scheduled for July 12.

Note that the remaining candidate CAN-1999-0358 (Digital "inc"
command) remains active, since it is affected by the "Same Time of
Discovery" and "Different Program, Same Code" content decisions.
Those content decisions have received little feedback since I posted
them for review on June 30th.

- Steve


Candidate: CAN-1999-0433
Interim-Decision: 19990712
Modified: 19990712-01
Announced: 19990617
Assigned: 19990607
Category: SF
Reference: SUSE:Mar28,1999
Reference: BUGTRAQ:Mar21,1999
Reference: XF:xfree86-temp-directories

XFree86 startx command is vulnerable to a symlink attack, allowing local
users to create files in restricted directories, possibly allowing
them to gain privileges or cause a denial of service.

  ADDREF XF:xfree86-temp-directories

   ACCEPT(4) Shostack, Northcutt, Prosser, Hill
   MODIFY(1) Frech

 Frech> Reference: XF:xfree86-temp-directories

Page Last Updated or Reviewed: May 22, 2007