Vulnerabilities > CVE-2012-5663 - Incomplete Cleanup vulnerability in Openbsd Textproc/Isearch
Attack vector
NETWORK Attack complexity
LOW Privileges required
NONE Confidentiality impact
NONE Integrity impact
HIGH Availability impact
NONE Summary
The isearch package (textproc/isearch) before 1.47.01nb1 uses the tempnam() function to create insecure temporary files into a publicly-writable area (/tmp).
Vulnerable Configurations
Part | Description | Count |
---|---|---|
Application | 1 |
Common Weakness Enumeration (CWE)
References
- http://gnats.netbsd.org/47360
- http://gnats.netbsd.org/47360
- http://www.openwall.com/lists/oss-security/2012/12/21/2
- http://www.openwall.com/lists/oss-security/2012/12/21/2
- http://www.openwall.com/lists/oss-security/2012/12/21/3
- http://www.openwall.com/lists/oss-security/2012/12/21/3
- https://access.redhat.com/security/cve/cve-2012-5663
- https://access.redhat.com/security/cve/cve-2012-5663
- https://security-tracker.debian.org/tracker/CVE-2012-5663
- https://security-tracker.debian.org/tracker/CVE-2012-5663