Description: A vulnerability has been identified in znew allowing malicious, local users escalate privileges.
The problem is a race condition in the way that znew and gzexe handles temporary files. This allows malicious, local users to launch a symlink attack, which could lead to overwriting arbitrary files that the user executing znew or gzexe got write access too.
The vulnerability in gzexe has been fixed earlier but has resurfaced later.
Customers of the Secunia Vulnerability Intelligence solutions will automatically receive updates when new information regarding this advisory is released.
If you have new information regarding this Secunia advisory or a product in our database, please send it to us using either our web form or email us at vuln@secunia.com.
Ideas, suggestions, and other feedback are most welcome.