CVE-2008-1687

Description

From CVE.org

The (1) maketemp and (2) mkstemp builtin functions in GNU m4 before 1.4.11 do not quote their output when a file is created, which might allow context-dependent attackers to trigger a macro expansion, leading to unspecified use of an incorrect filename.

Statement

Red Hat does not consider this to be a security issue. After careful analysis of this issue the Red Hat Product Security has determined that this bug has no security impact outside of expected m4 behavior.

Frequently Asked Questions

Want to get errata notifications? Sign up here.