Candidate: CVE-2013-3368 PublicDate: 2013-08-23 16:55:00 UTC References: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-3368 http://lists.bestpractical.com/pipermail/rt-announce/2013-May/000226.html Description: bin/rt in Request Tracker (RT) 3.8.x before 3.8.17 and 4.0.x before 4.0.13 allows local users to overwrite arbitrary files via a symlink attack on a temporary file with predictable name. Ubuntu-Description: Notes: Bugs: Priority: medium Discovered-by: Assigned-to: CVSS: Patches_request-tracker3.8: upstream_request-tracker3.8: released (3.8.17) lucid_request-tracker3.8: ignored (reached end-of-life) precise_request-tracker3.8: ignored (reached end-of-life) precise/esm_request-tracker3.8: DNE (precise was needed) quantal_request-tracker3.8: DNE raring_request-tracker3.8: DNE saucy_request-tracker3.8: DNE trusty_request-tracker3.8: DNE trusty/esm_request-tracker3.8: DNE utopic_request-tracker3.8: DNE vivid_request-tracker3.8: DNE vivid/stable-phone-overlay_request-tracker3.8: DNE vivid/ubuntu-core_request-tracker3.8: DNE wily_request-tracker3.8: DNE xenial_request-tracker3.8: DNE yakkety_request-tracker3.8: DNE zesty_request-tracker3.8: DNE devel_request-tracker3.8: DNE Patches_request-tracker4: upstream_request-tracker4: released (4.0.13) lucid_request-tracker4: DNE precise_request-tracker4: ignored (reached end-of-life) precise/esm_request-tracker4: DNE (precise was needed) quantal_request-tracker4: ignored (reached end-of-life) raring_request-tracker4: ignored (reached end-of-life) saucy_request-tracker4: not-affected (4.0.13-1) trusty_request-tracker4: not-affected (4.0.19-1) trusty/esm_request-tracker4: DNE (trusty was not-affected [4.0.19-1]) utopic_request-tracker4: not-affected (4.0.19-1) vivid_request-tracker4: not-affected (4.0.19-1) vivid/stable-phone-overlay_request-tracker4: DNE vivid/ubuntu-core_request-tracker4: DNE wily_request-tracker4: not-affected (4.0.19-1) xenial_request-tracker4: not-affected (4.0.19-1) yakkety_request-tracker4: not-affected (4.0.19-1) zesty_request-tracker4: not-affected (4.0.19-1) devel_request-tracker4: not-affected (4.0.19-1)