Security Advisory

CVE-2008-1687

CVE vulnerability detail - eXtreme Datacenter Security Operations

Published 2008-04-09 19:00:00
Last updated 2024-08-07 08:32:01
Assigner mitre
CVSS score not scored
State PUBLISHED

Description

The (1) maketemp and (2) mkstemp builtin functions in GNU m4 before 1.4.11 do not quote their output when a file is created, which might allow context-dependent attackers to trigger a macro expansion, leading to unspecified use of an incorrect filename.