In swtpm before 0.4.2 and 0.5.x before 0.5.1, a local attacker may be able to overwrite arbitrary files via a symlink attack against a temporary file such as TMP2-00.permall.
{ "availability": "No subscription required", "ubuntu_priority": "medium", "binaries": [ { "binary_version": "0.6.3-0ubuntu3", "binary_name": "swtpm" }, { "binary_version": "0.6.3-0ubuntu3", "binary_name": "swtpm-dbgsym" }, { "binary_version": "0.6.3-0ubuntu3", "binary_name": "swtpm-tools" }, { "binary_version": "0.6.3-0ubuntu3", "binary_name": "swtpm-tools-dbgsym" } ] }