Candidate: CVE-2014-5254 PublicDate: 2019-11-21 23:15:00 UTC References: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-5254 Description: xcfa before 5.0.1 creates temporary files insecurely which could allow local users to launch a symlink attack and overwrite arbitrary files. Ubuntu-Description: Notes: seth-arnold> Extensive unsafe use of /tmp leads me to believe the problems extend beyond just symlink or just hardlink issues, thus I'm not tagging this with the symlink-restriction or hardlink-restriction tags and I'm setting the Priority to "medium" rather than "low" as a result. Bugs: http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=756600 Priority: medium Discovered-by: Steve Kemp Assigned-to: CVSS: nvd: CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:H/A:N [4.7 MEDIUM] Patches_xcfa: upstream_xcfa: needed lucid_xcfa: ignored (reached end-of-life) precise_xcfa: ignored (reached end-of-life) precise/esm_xcfa: DNE (precise was needed) trusty_xcfa: ignored (reached end-of-life) trusty/esm_xcfa: DNE (trusty was needed) utopic_xcfa: ignored (reached end-of-life) vivid_xcfa: ignored (reached end-of-life) vivid/stable-phone-overlay_xcfa: DNE vivid/ubuntu-core_xcfa: DNE wily_xcfa: ignored (reached end-of-life) xenial_xcfa: not-affected (5.0.1-1) yakkety_xcfa: ignored (reached end-of-life) zesty_xcfa: ignored (reached end-of-life) artful_xcfa: ignored (reached end-of-life) bionic_xcfa: not-affected (5.0.1-1) cosmic_xcfa: not-affected (5.0.1-1) disco_xcfa: not-affected (5.0.1-1) devel_xcfa: not-affected (5.0.1-1)