Vulnerability   
Search   
    Search 324607 CVE descriptions
and 145615 test descriptions,
access 10,000+ cross references.
Tests   CVE   All  

CVE ID:CVE-2012-2093
Description:src/common/latex.py in Gajim 0.15 allows local users to overwrite arbitrary files via a symlink attack on a temporary latex file, related to the get_tmpfile_name function.
Test IDs: 1.3.6.1.4.1.25623.1.0.71257   1.3.6.1.4.1.25623.1.0.71258   1.3.6.1.4.1.25623.1.0.864189   1.3.6.1.4.1.25623.1.0.864332   1.3.6.1.4.1.25623.1.0.864187  
Cross References: Common Vulnerability Exposure (CVE) ID: CVE-2012-2093
48695
http://secunia.com/advisories/48695
48794
http://secunia.com/advisories/48794
53017
http://www.securityfocus.com/bid/53017
FEDORA-2012-6001
http://lists.fedoraproject.org/pipermail/package-announce/2012-April/079237.html
FEDORA-2012-6061
http://lists.fedoraproject.org/pipermail/package-announce/2012-April/079241.html
FEDORA-2012-6161
http://lists.fedoraproject.org/pipermail/package-announce/2012-April/079169.html
GLSA-201208-04
http://security.gentoo.org/glsa/glsa-201208-04.xml
[oss-security] 20120410 RE: gajim insecure file creation when using latex
http://www.openwall.com/lists/oss-security/2012/04/10/15
[oss-security] 20120410 gajim insecure file creation when using latex
http://www.openwall.com/lists/oss-security/2012/04/10/6
gajim-gettmpfilename-symlink(74869)
https://exchange.xforce.ibmcloud.com/vulnerabilities/74869
http://hg.gajim.org/gajim/rev/f046e4aaf7d4
http://hg.gajim.org/gajim/rev/f046e4aaf7d4
https://trac.gajim.org/changeset/13759/src/common/latex.py
https://trac.gajim.org/changeset/13759/src/common/latex.py




© 1998-2025 E-Soft Inc. All rights reserved.