DSA-279

    Dashboard / Vulnerabilities / DSA-279

    DSA-279

    Published: 7 Apr 2003Last Modified: 4 Jul 2022

    Summary: metrics - insecure temporary file creation

    Details: Paul Szabo and Matt Zimmerman discovered two similar problems in metrics, a tools for software metrics. Two scripts in this package, "halstead" and "gather\_stats", open temporary files without taking appropriate security precautions. "halstead" is installed as a user program, while "gather\_stats" is only used in an auxiliary script included in the source code. These vulnerabilities could allow a local attacker to overwrite files owned by the user running the scripts, including root. The stable distribution (woody) is not affected since it doesn't contain a metrics package anymore. For the old stable distribution (potato) this problem has been fixed in version 1.0-1.1. The unstable distribution (sid) is not affected since it doesn't contain a metrics package anymore. We recommend that you upgrade your metrics package.

    References:

    Affected packages

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High