FreeBSD : mono -- 'System.CodeDom.Compiler' Insecure Temporary Creation (5a39a22e-5478-11db-8f1a-000a48049292)
Medium Nessus Plugin ID 22516
SynopsisThe remote FreeBSD host is missing a security-related update.
DescriptionSebastian Krahmer reports :
Sebastian Krahmer of the SuSE security team discovered that the System.CodeDom.Compiler classes used temporary files in an insecure way. This could allow a symbolic link attack to create or overwrite arbitrary files with the privileges of the user invoking the program.
Under some circumstances, a local attacker could also exploit this to inject arbitrary code into running Mono processes.
SolutionUpdate the affected package.