The transform_save function in transform.c in Augeas before 1.0.0 allows local users to overwrite arbitrary files and obtain sensitive information via a symlink attack on a .augnew file.
{
"availability": "No subscription required",
"binaries": [
{
"binary_version": "1.1.0-0ubuntu2",
"binary_name": "augeas-dbg"
},
{
"binary_version": "1.1.0-0ubuntu2",
"binary_name": "augeas-doc"
},
{
"binary_version": "1.1.0-0ubuntu2",
"binary_name": "augeas-lenses"
},
{
"binary_version": "1.1.0-0ubuntu2",
"binary_name": "augeas-tools"
},
{
"binary_version": "1.1.0-0ubuntu2",
"binary_name": "libaugeas-dev"
},
{
"binary_version": "1.1.0-0ubuntu2",
"binary_name": "libaugeas0"
}
]
}