IPMenu Log File Symbolic Link Vulnerability
BID:10269
Info
IPMenu Log File Symbolic Link Vulnerability
| Bugtraq ID: | 10269 |
| Class: | Design Error |
| CVE: | |
| Remote: | No |
| Local: | Yes |
| Published: | May 04 2004 12:00AM |
| Updated: | May 04 2004 12:00AM |
| Credit: | Discovery of this issue is credited to Akira Yoshiyama. |
| Vulnerable: |
ipmenu Netfilter/IPtables Rule Editor 0.0.3 ipmenu Netfilter/IPtables Rule Editor 0.0.2 ipmenu Netfilter/IPtables Rule Editor 0.0.1 Debian Linux 3.0 sparc Debian Linux 3.0 s/390 Debian Linux 3.0 ppc Debian Linux 3.0 mipsel Debian Linux 3.0 mips Debian Linux 3.0 m68k Debian Linux 3.0 ia-64 Debian Linux 3.0 ia-32 Debian Linux 3.0 hppa Debian Linux 3.0 arm Debian Linux 3.0 alpha Debian Linux 3.0 |
| Not Vulnerable: | |
Discussion
IPMenu Log File Symbolic Link Vulnerability
It has been reported that ipmenu is affected by a symbolic link vulnerability. This issue is due to a design error that allows for the creation of temporary files in an insecure fashion, facilitating symbolic links attacks.
This issue may be leveraged to create a system wide denial of service condition. This issue may also be leveraged to escalate privileges on the affected system, although this is currently unverified.
It has been reported that ipmenu is affected by a symbolic link vulnerability. This issue is due to a design error that allows for the creation of temporary files in an insecure fashion, facilitating symbolic links attacks.
This issue may be leveraged to create a system wide denial of service condition. This issue may also be leveraged to escalate privileges on the affected system, although this is currently unverified.
Exploit / POC
IPMenu Log File Symbolic Link Vulnerability
No exploit is required to leverage this issue.
No exploit is required to leverage this issue.
Solution / Fix
IPMenu Log File Symbolic Link Vulnerability
Solution:
Debian security advisory DSA 907-1 has been released; please see the referenced advisory for further details.
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution:
Debian security advisory DSA 907-1 has been released; please see the referenced advisory for further details.
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.