RSS   Vulnerabilities for 'At-spi2-atk'   RSS

2012-08-31
 
CVE-2012-3378

CWE-310
 

 
The register_application function in atk-adaptor/bridge.c in GNOME at-spi2-atk 2.5.2 does not seed the random number generator and generates predictable temporary file names, which makes it easier for local users to create or truncate files via a symlink attack on a temporary socket file in /tmp/at-spi2.

 

 >>> Vendor: Gnome 58 Products
GDM
Gnome libs
Esound
Gnorpm
Libgtop daemon
Bonobo
Gnome-terminal
Gnome-lokkit
Gtkhtml
EOG
Batalla naval
Gdkpixbuf
GPDF
Libvte4
Libzvt2
Epiphany
Gedit
Networkmanager
Evolution
Libgda2
Dwarf http server
Screensaver
Dhcdbd
Gconf
Power manager
Ekiga
Balsa
Gnome-vfs
Gnumeric
Gnome
YELP
GLIB
Vinagre
Rhythmbox
Nautilus-python
Evolution-data-server
Gmime
Gnome-shell
Tomboy
Libsoup
Ifcfg-rh plug-in
Empathy
Update-manager-core
Gdk-pixbuf
Libgdata
At-spi2-atk
Librsvg
Gnome-keyring
Evince
Gnome display manager
Gnome online accounts
VALA
Byzanz
Eye of gnome
Libgsf
Libsocialweb
Gtk-vnc
Libcroco


Copyright 2017, cxsecurity.com