Candidate: CVE-2014-4150 PublicDate: 2018-07-20 17:29:00 UTC References: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-4150 http://www.openwall.com/lists/oss-security/2014/06/13/5 Description: The scheme48-send-definition function in cmuscheme48.el in Scheme 48 allows local users to write to arbitrary files via a symlink attack on /tmp/s48lose.tmp. Ubuntu-Description: Notes: Bugs: http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=748766 Priority: low Discovered-by: Steve Kemp Assigned-to: CVSS: nvd: CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N [5.5 MEDIUM] Tags_scheme48: hardlink-restriction symlink-restriction Patches_scheme48: upstream: http://www.s48.org/cgi-bin/hgwebdir.cgi/s48/rev/a44624256297 upstream_scheme48: released (1.9-4) lucid_scheme48: ignored (reached end-of-life) precise_scheme48: released (1.8+dfsg-1+deb6u1ubuntu12.04.1) precise/esm_scheme48: DNE (precise was released [1.8+dfsg-1+deb6u1ubuntu12.04.1]) saucy_scheme48: ignored (reached end-of-life) trusty_scheme48: ignored (reached end-of-life) trusty/esm_scheme48: DNE (trusty was needed) utopic_scheme48: not-affected (1.9-4) vivid_scheme48: not-affected (1.9-4) vivid/stable-phone-overlay_scheme48: DNE vivid/ubuntu-core_scheme48: DNE wily_scheme48: not-affected (1.9-4) xenial_scheme48: not-affected (1.9-4) yakkety_scheme48: not-affected (1.9-4) zesty_scheme48: not-affected (1.9-4) artful_scheme48: not-affected (1.9-4) bionic_scheme48: not-affected (1.9-4) cosmic_scheme48: not-affected (1.9-4) disco_scheme48: not-affected (1.9-4) devel_scheme48: not-affected (1.9-4)