CVE-2011-2684

NameCVE-2011-2684
Descriptionfoo2zjs before 20110722dfsg-3ubuntu1 as packaged in Ubuntu, 20110722dfsg-1 as packaged in Debian unstable, and 20090908dfsg-5.1+squeeze0 as packaged in Debian squeeze create temporary files insecurely, which allows local users to write over arbitrary files via a symlink attack on /tmp/foo2zjs.
SourceCVE (at NVD; CERT, LWN, oss-sec, fulldisc, bugtraq, EDB, Metasploit, Red Hat, Ubuntu, Gentoo, SUSE bugzilla/CVE, Mageia, GitHub code/issues, web search, more)
NVD severitylow
Debian Bugs633870

Vulnerable and fixed packages

The table below lists information on source packages.

Source PackageReleaseVersionStatus
foo2zjs (PTS)stretch20160902dfsg0-2fixed
buster20171202dfsg0-2fixed
bullseye20200505dfsg0-1fixed
bookworm, sid20200505dfsg0-2fixed

The information below is based on the following data on fixed versions.

PackageTypeReleaseFixed VersionUrgencyOriginDebian Bugs
foo2zjssourcesqueeze20090908dfsg-5.1+squeeze0
foo2zjssource(unstable)20110722dfsg-1low633870

Notes

[lenny] - foo2zjs <no-dsa> (Minor issue)

Search for package or bug name: Reporting problems