Candidate: CVE-2011-4617 PublicDate: 2011-12-31 01:55:00 UTC References: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-4617 http://openwall.com/lists/oss-security/2011/12/19/2 Description: virtualenv.py in virtualenv before 1.5 allows local users to overwrite arbitrary files via a symlink attack on a certain file in /tmp/. Ubuntu-Description: Notes: Bugs: Priority: medium Discovered-by: Assigned-to: CVSS: Patches_python-virtualenv: upstream: https://bitbucket.org/ianb/virtualenv/changeset/8be37c509fe5 upstream_python-virtualenv: released (1.5) hardy_python-virtualenv: DNE lucid_python-virtualenv: ignored (reached end-of-life) maverick_python-virtualenv: ignored (reached end-of-life) natty_python-virtualenv: ignored (reached end-of-life) oneiric_python-virtualenv: not-affected (1.6.4-0ubuntu1) precise_python-virtualenv: not-affected (1.6.4-0ubuntu1) quantal_python-virtualenv: not-affected (1.6.4-0ubuntu1) raring_python-virtualenv: not-affected (1.6.4-0ubuntu1) saucy_python-virtualenv: not-affected (1.6.4-0ubuntu1) devel_python-virtualenv: not-affected (1.6.4-0ubuntu1)