Vulnerabilities > CVE-2007-4462 - Local Privilege Escalation vulnerability in po4a GetTextization.Failed.PO

047910
CVSS 3.3 - LOW
Attack vector
LOCAL
Attack complexity
MEDIUM
Privileges required
NONE
Confidentiality impact
NONE
Integrity impact
PARTIAL
Availability impact
PARTIAL
local
po4a
nessus

Summary

lib/Locale/Po4a/Po.pm in po4a before 0.32 allows local users to overwrite arbitrary files via a symlink attack on the gettextization.failed.po temporary file.

Vulnerable Configurations

Part Description Count
Application
Po4A
1

Nessus

NASL familyGentoo Local Security Checks
NASL idGENTOO_GLSA-200709-04.NASL
descriptionThe remote host is affected by the vulnerability described in GLSA-200709-04 (po4a: Insecure temporary file creation) The po4a development team reported a race condition in the gettextize() function when creating the file
last seen2020-06-01
modified2020-06-02
plugin id26094
published2007-09-24
reporterThis script is Copyright (C) 2007-2019 Tenable Network Security, Inc.
sourcehttps://www.tenable.com/plugins/nessus/26094
titleGLSA-200709-04 : po4a: Insecure temporary file creation