<title>gEDA: Insecure temporary file creation</title>
An insecure temporary file usage has been reported in gEDA, allowing for
symlink attacks.
<announced>March 07, 2009</announced>
<revised>March 07, 2009: 01</revised>
gEDA is an Electronic Design Automation tool used for electrical
circuit design.
Dmitry E. Oboukhov reported an insecure temporary file usage within the script.
A local attacker could perform symlink attacks to overwrite arbitrary
files with the privileges of the user running the application.
There is no known workaround at this time.
All gEDA users should upgrade to the latest version:
# emerge --sync
# emerge --ask --oneshot --verbose &quot;&gt;=sci-electronics/geda-1.4.0-r1&quot;</code>
<uri link="">CVE-2008-5148</uri>
