CVE-2005-1707 Gentoo webapp-config Temporary File Privilege Escalation

Timeline :

Vulnerability discovered by Eric Romang the 2005-05-07
Vendor notified the 2005-05-07
Coordinated vulnerability disclosure the 2005-05-22

Reference(s) :

CVE-2005-1707
OSVDB-16746

Affected version(s) :

webapp-config before or equal to 1.10-r14

Description :

The fn_show_postinst function in Gentoo webapp-config before 1.10-r14 allows local users to overwrite arbitrary files via a symlink attack on the postinst.txt temporary file.