Kamailio CVE-2013-7426 Insecure Temporary File Creation Vulnerability
BID:100537
CVE-2013-7426 |Info
Kamailio CVE-2013-7426 Insecure Temporary File Creation Vulnerability
| Bugtraq ID: | 100537 |
| Class: | Design Error |
| CVE: |
CVE-2013-7426 |
| Remote: | No |
| Local: | Yes |
| Published: | Aug 29 2017 12:00AM |
| Updated: | Aug 29 2017 12:00AM |
| Credit: | Helmut Grohne |
| Vulnerable: |
Kamailio Kamailio 4.0.1-1 |
| Not Vulnerable: |
Kamailio Kamailio 4.0.2-1 |
Discussion
Kamailio CVE-2013-7426 Insecure Temporary File Creation Vulnerability
Kamailio is prone to an insecure temporary-file-creation vulnerability.
An attacker with local access could potentially exploit this issue to perform symbolic-link attacks, overwriting arbitrary files in the context of the affected application, which may result in a denial of service. Other attacks may also be possible.
Kamailio is prone to an insecure temporary-file-creation vulnerability.
An attacker with local access could potentially exploit this issue to perform symbolic-link attacks, overwriting arbitrary files in the context of the affected application, which may result in a denial of service. Other attacks may also be possible.
Exploit / POC
Kamailio CVE-2013-7426 Insecure Temporary File Creation Vulnerability
An attacker uses readily available commands to exploit this issue.
An attacker uses readily available commands to exploit this issue.
Solution / Fix
Kamailio CVE-2013-7426 Insecure Temporary File Creation Vulnerability
Solution:
Updates are available. Please see the references or vendor advisory for more information.
Solution:
Updates are available. Please see the references or vendor advisory for more information.
References
Kamailio CVE-2013-7426 Insecure Temporary File Creation Vulnerability
References:
References:
- [PATCH 1/2] fix fifo and ctl defaults pointing to unsecure /tmp dir (debian.org)
- Debian Bug report logs - #712083 kamailio: CVE-2013-7426: insecure default fifo (Debian)
- Kamailio Homepage (Kamailio)
- multiple /tmp file vulnerabilities #48 (Github)
- Re: kamailio: multiple /tmp file vulnerabilities (openwall)