Debian Security Advisory DSA 661-1 (f2c)

Information

Severity

Severity

Low

Family

Family

Debian Local Security Checks

CVSSv2 Base

CVSSv2 Base

2.1

CVSSv2 Vector

CVSSv2 Vector

AV:L/AC:L/Au:N/C:P/I:N/A:N

Solution Type

Solution Type

Vendor Patch

Created

Created

14 years ago

Modified

Modified

4 years ago

Summary

The remote host is missing an update to f2c announced via advisory DSA 661-1.

Insight

Insight

Javier Fernández-Sanguino Peña from the Debian Security Audit project discovered that f2c and fc, which are both part of the f2c package, a fortran 77 to C/C++ translator, open temporary files insecurely and are hence vulnerable to a symlink attack. The Common Vulnerabilities and Exposures project identifies the following vulnerabilities: CVE-2005-0017 Multiple insecure temporary files in the f2c translator. CVE-2005-0018 Two insecure temporary files in the f2 shell script. For the stable distribution (woody) these problems have been fixed in version 20010821-3.1 For the unstable distribution (sid) these problems will be fixed soon. We recommend that you upgrade your f2c package.

Solution

Solution

https://secure1.securityspace.com/smysecure/catid.html?in=DSA%20661-1

Common Vulnerabilities and Exposures (CVE)

Want the latest vulnerabilities news?

Sign up to stay up to date. It is free and always will be.

Processing. Please wait...

We care about the protection of your data. Read our Privacy Policy.