CVE-2015-4156 Information

Description

GNU Parallel before 20150522 (Nepal) when using (1) –cat or (2) –fifo with –sshlogin allows local users to write to arbitrary files via a symlink attack on a temporary file.

Reference

http://lists.gnu.org/archive/html/parallel/2015-04/msg00045.html http://lists.gnu.org/archive/html/parallel/2015-05/msg00024.html http://lists.opensuse.org/opensuse-updates/2015-05/msg00090.html http://www.securityfocus.com/bid/74961

Share on: