ALAS-2012-064


Amazon Linux AMI Security Advisory: ALAS-2012-64
Advisory Release Date: 2014-09-14 16:09 Pacific
Severity: Low
References: CVE-2012-1088 

Issue Overview:

iproute2 before 3.3.0 allows local users to overwrite arbitrary files via a symlink attack on a temporary file used by (1) configure or (2) examples/dhcp-client-script.


Affected Packages:

iproute


Issue Correction:
Run yum update iproute to update your system.

New Packages:
i686:
    iproute-doc-3.2.0-3.7.amzn1.i686
    iproute-devel-3.2.0-3.7.amzn1.i686
    iproute-3.2.0-3.7.amzn1.i686
    iproute-debuginfo-3.2.0-3.7.amzn1.i686

src:
    iproute-3.2.0-3.7.amzn1.src

x86_64:
    iproute-doc-3.2.0-3.7.amzn1.x86_64
    iproute-devel-3.2.0-3.7.amzn1.x86_64
    iproute-debuginfo-3.2.0-3.7.amzn1.x86_64
    iproute-3.2.0-3.7.amzn1.x86_64