Submitted by KeesCook on Mon, 2005-04-04 12:01
Description:
===========================================================
Ubuntu Security Notice USN-104-1 April 04, 2005
sharutils vulnerability
https://bugzilla.ubuntu.com/show_bug.cgi?id=8459
===========================================================
A security issue affects the following Ubuntu releases:
Ubuntu 4.10 (Warty Warthog)
The following packages are affected:
sharutils
The problem can be corrected by upgrading the affected package to
version 1:4.2.1-10ubuntu0.2. In general, a standard system upgrade is
sufficient to effect the necessary changes.
Details follow:
Joey Hess discovered that "unshar" created temporary files in an
insecure manner. This could allow a symbolic link attack to create or
overwrite arbitrary files with the privileges of the user invoking the
program.


