GNU Parallel Arbitrary File Write Vulnerability in CVE-2015-4155)
GNU Parallel Arbitrary File Write Vulnerability in CVE-2015-4155)
Release date:
Updated on:
Affected Systems:
GNU Parallel <20150522 (Nepal)
Description:
CVE (CAN) ID: CVE-2015-4155
GNU parallel is a command line tool applicable to Linux or other Unix-like operating systems.
In versions earlier than GNU Parallel 20150422, when -- pipe, -- tmux, -- cat, -- fifo, -- compress is used, local users are attacked by symbols of temporary files, this vulnerability allows you to write arbitrary files.
<* Source: vendor
*>
Suggestion:
Vendor patch:
GNU
---
The vendor has released a patch to fix this security problem. Please download it from the vendor's homepage:
Http://lists.gnu.org/archive/html/parallel/2015-05/msg00024.html
Http://lists.opensuse.org/opensuse-updates/2015-05/msg00090.html
Http://lists.gnu.org/archive/html/parallel/2015-04/msg00045.html
This article permanently updates the link address: