
DescriptionMultiple scripts on SuSE Linux 9.0 allow local users to overwrite arbitrary files via a symlink attack on (1) /tmp/fvwm-bug created by fvwm-bug, (2) /tmp/wmmenu created by wm-oldmenu2new, (3) /tmp/rates created by x11perfcomp, (4) /tmp/xf86debug.1.log created by xf86debug, (5) /tmp/.winpopup-new created by, or (6) /tmp/initrd created by lvmcreate_initrd.
SourceCVE (at NVD; CERT, LWN, oss-sec, fulldisc, Red Hat, Ubuntu, Gentoo, SUSE bugzilla/CVE, GitHub advisories/code/issues, web search, more)

Vulnerable and fixed packages

The table below lists information on source packages.

Source PackageReleaseVersionStatus
fvwm (PTS)jessie1:2.6.5.ds-3fixed
buster, bullseye1:2.6.8-1fixed
sid, trixie, bookworm1:2.7.0-2fixed

The information below is based on the following data on fixed versions.

PackageTypeReleaseFixed VersionUrgencyOriginDebian Bugs
fvwmsource(unstable)(not affected)
lvm10source(unstable)(not affected)
xbase-clientssource(unstable)(not affected)


- fvwm <not-affected> (Used mktemp)
- xbase-clients <not-affected> (x11perfcomp uses mkdir atomically)
- lvm10 <not-affected> (does not contain lvmcreate_initrd)

