{
  "modified": "2025-04-11T00:51:21Z",
  "published": "2012-08-31T18:55:02Z",
  "id": "CVE-2012-3378",
  "details": "The register_application function in atk-adaptor/bridge.c in GNOME at-spi2-atk 2.5.2 does not seed the random number generator and generates predictable temporary file names, which makes it easier for local users to create or truncate files via a symlink attack on a temporary socket file in /tmp/at-spi2.",
  "references": [
    {
      "type": "REPORT",
      "url": "https://bugzilla.gnome.org/show_bug.cgi?id=678348"
    },
    {
      "type": "WEB",
      "url": "http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=678026"
    },
    {
      "type": "WEB",
      "url": "http://www.openwall.com/lists/oss-security/2012/07/05/1"
    },
    {
      "type": "WEB",
      "url": "http://www.openwall.com/lists/oss-security/2012/07/06/3"
    }
  ]
}
