CVE-2007-4631

Publication date 31 August 2007

Last updated 17 July 2025


Ubuntu priority

Description

The DataLoader::doStart function in dataloader.cpp in QGit 1.5.6 and other versions up to 2pre1 allows local users to overwrite arbitrary files and execute arbitrary code via a symlink attack on temporary files with predictable filenames.

Status

Package Ubuntu Release Status
qgit 8.04 LTS hardy
Fixed 1.5.5-1.1
7.10 gutsy
Fixed 1.5.5-1.1
7.04 feisty Ignored end of life, was needed
6.10 edgy Ignored end of life, was needed
6.06 LTS dapper Not in release


Access our resources on patching vulnerabilities