In swtpm before 0.4.2 and 0.5.x before 0.5.1, a local attacker may be able to overwrite arbitrary files via a symlink attack against a temporary file such as TMP2-00.permall.
{ "availability": "No subscription required", "binaries": [ { "binary_name": "swtpm", "binary_version": "0.6.3-0ubuntu3" }, { "binary_name": "swtpm-dbgsym", "binary_version": "0.6.3-0ubuntu3" }, { "binary_name": "swtpm-tools", "binary_version": "0.6.3-0ubuntu3" }, { "binary_name": "swtpm-tools-dbgsym", "binary_version": "0.6.3-0ubuntu3" } ], "ubuntu_priority": "medium" }