Mandrake Linux Security Advisory : lm_sensors (MDKSA-2005:149)
Low Nessus Plugin ID 19905
SynopsisThe remote Mandrake Linux host is missing one or more security updates.
DescriptionJavier Fernandez-Sanguino Pena discovered that the pwmconfig script in the lm_sensors package created temporary files in an insecure manner.
This could allow a symlink attack to create or overwrite arbitrary files with full root privileges because pwmconfig is typically executed by root.
The updated packages have been patched to correct this problem by using mktemp to create the temporary files.
SolutionUpdate the affected packages.