|Main Archive Page > Month Archives > oss-security archives|
rocksndiamonds creates its ~/.rocksndiamonds/ directory as
world-writable. This could allow a local attacker to replace a cache
file with a symbolic link to a file they would not otherwise have access
to, and the next time the victim loaded the game, it would be
Could a CVE be assigned to this please?
-- Vincent Danen / Red Hat Security Response Team