Directory traversal vulnerability in device-linux.c in the router
advertisement daemon (radvd) before 1.8.2 allows local users to overwrite
arbitrary files, and remote attackers to overwrite certain files, via a ..
(dot dot) in an interface name. NOTE: this can be leveraged with a symlink
to overwrite arbitrary files.
mdeslaur> upstream patch may be incorrect, see
mdeslaur> issue was actually fixed in 1.8.3 because of incorrect patch
Updated: 2015-07-29 20:40:04 UTC (commit 9756)