Vulnerability   
Search   
    Search 324607 CVE descriptions
and 145615 test descriptions,
access 10,000+ cross references.
Tests   CVE   All  

CVE ID:CVE-2011-1920
Description:The make include files in NetBSD before 1.6.2, as used in pmake 1.111 and other products, allow local users to overwrite arbitrary files via a symlink attack on a /tmp/_depend##### temporary file, related to (1) bsd.lib.mk and (2) bsd.prog.mk.
Test IDs: 1.3.6.1.4.1.25623.1.1.10.2013.0331   1.3.6.1.4.1.25623.1.0.121055  
Cross References: Common Vulnerability Exposure (CVE) ID: CVE-2011-1920
47878
http://www.securityfocus.com/bid/47878
[oss-security] 20110516 CVE Request -- pmake -- Use of insecure temporary file for 'depend' target
http://openwall.com/lists/oss-security/2011/05/16/2
[oss-security] 20110516 Re: CVE Request -- pmake -- Use of insecure temporary file for 'depend' target
http://openwall.com/lists/oss-security/2011/05/16/8
http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=626673
http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=626673
http://cvsweb.netbsd.org/bsdweb.cgi/src/share/mk/bsd.lib.mk.diff?r1=1.239&r2=1.240&f=h
http://cvsweb.netbsd.org/bsdweb.cgi/src/share/mk/bsd.lib.mk.diff?r1=1.239&r2=1.240&f=h
http://cvsweb.netbsd.org/bsdweb.cgi/src/share/mk/bsd.prog.mk.diff?r1=1.192&r2=1.193&f=h
http://cvsweb.netbsd.org/bsdweb.cgi/src/share/mk/bsd.prog.mk.diff?r1=1.192&r2=1.193&f=h
https://bugzilla.redhat.com/show_bug.cgi?id=705090
https://bugzilla.redhat.com/show_bug.cgi?id=705090
https://bugzilla.redhat.com/show_bug.cgi?id=705100
https://bugzilla.redhat.com/show_bug.cgi?id=705100
pmake-depend-symlink(67495)
https://exchange.xforce.ibmcloud.com/vulnerabilities/67495




© 1998-2025 E-Soft Inc. All rights reserved.