Title: Multiple Vendor man(1) 'makewhatis' Insecure /tmp Files Vulnerability
Severity: MODERATE
Description:
Due to insecure handling of /tmp files by the 'makewhatis' portion of the man(1) command it is possible for a user to manipulate files to which they should not have access or to possibly to elevate their privileges. This is possible because 'makewhatis' creates non-randomly named files in the /tmp directory which are subject to symlink attacks. man 1.5e and higher is vulnerable.
Affected Products:
- Caldera OpenLinux 2.3.0
- Caldera OpenLinux 2.4.0
- MandrakeSoft Linux Mandrake 6.0.0
- MandrakeSoft Linux Mandrake 6.1.0
- MandrakeSoft Linux Mandrake 7.0.0
- MandrakeSoft Linux Mandrake 7.1.0
- RedHat Linux 5.2.0 alpha
- RedHat Linux 5.2.0 i386
- RedHat Linux 5.2.0 sparc
- RedHat Linux 6.0.0
- RedHat Linux 6.0.0 alpha
- RedHat Linux 6.0.0 sparc
- RedHat Linux 6.1.0 alpha
- RedHat Linux 6.1.0 i386
- RedHat Linux 6.1.0 sparc
- RedHat Linux 6.2.0
- RedHat Linux 6.2.0 alpha
- RedHat Linux 6.2.0 i386
- RedHat Linux 6.2.0 sparc
- RedHat man-1.5f-1.i386.rpm 0.0.0
- RedHat man-1.5h1-1.i386.rpm 0.0.0
Juniper Networks provides this content via a wide variety of sources and production methods. If notified of errors or omissions in the content of this page, Juniper Networks, at its discretion, will modify or remove the page or leave the content as is, depending on various factors including but not limited to the reputation and authority of the party providing the notification. Please use the contact information displayed elsewhere on this page to report any errors or omissions regarding the content on this page.