KSymoops KSymoops-GZNM Insecure Temporary File Handling Symbolic Link Vulnerability
BID:10516
Info
KSymoops KSymoops-GZNM Insecure Temporary File Handling Symbolic Link Vulnerability
| Bugtraq ID: | 10516 |
| Class: | Access Validation Error |
| CVE: |
CVE-2004-0581 |
| Remote: | No |
| Local: | Yes |
| Published: | Jun 10 2004 12:00AM |
| Updated: | Jul 12 2009 05:16AM |
| Credit: | Discovery of this vulnerability is credited to Geoffrey Lee. |
| Vulnerable: |
Mandriva Linux Mandrake 10.0 AMD64 Mandriva Linux Mandrake 10.0 Mandriva Linux Mandrake 9.2 amd64 Mandriva Linux Mandrake 9.2 Mandriva Linux Mandrake 9.1 ppc Mandriva Linux Mandrake 9.1 MandrakeSoft Corporate Server 2.1 x86_64 MandrakeSoft Corporate Server 2.1 GNU Ksymoops 2.4.9 GNU Ksymoops 2.4.8 GNU Ksymoops 2.4.5 |
| Not Vulnerable: | |
Discussion
KSymoops KSymoops-GZNM Insecure Temporary File Handling Symbolic Link Vulnerability
Ksymoops ships with several scripts, one of these scripts is 'ksymoops-gznm'. It is reported that the 'ksymoops-gznm' script is prone to a local insecure temporary file handling symbolic link vulnerability. This issue is due to a design error that allows the application to insecurely write to a temporary file that is created with a predictable file name. The script will write to this file before verifying its existence; this would facilitate a symbolic link attack.
Ksymoops ships with several scripts, one of these scripts is 'ksymoops-gznm'. It is reported that the 'ksymoops-gznm' script is prone to a local insecure temporary file handling symbolic link vulnerability. This issue is due to a design error that allows the application to insecurely write to a temporary file that is created with a predictable file name. The script will write to this file before verifying its existence; this would facilitate a symbolic link attack.
Exploit / POC
KSymoops KSymoops-GZNM Insecure Temporary File Handling Symbolic Link Vulnerability
Currently we are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Currently we are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution / Fix
KSymoops KSymoops-GZNM Insecure Temporary File Handling Symbolic Link Vulnerability
Solution:
Mandrake has released an advisory(MDKSA-2004:060) and updates to address this issue in Mandrake Linux. Users are advised to read the referenced advisory for further details regarding obtaining and applying appropriate updates.
GNU Ksymoops 2.4.5
GNU Ksymoops 2.4.8
GNU Ksymoops 2.4.9
Solution:
Mandrake has released an advisory(MDKSA-2004:060) and updates to address this issue in Mandrake Linux. Users are advised to read the referenced advisory for further details regarding obtaining and applying appropriate updates.
GNU Ksymoops 2.4.5
-
Mandrake ksymoops-2.4.5-1.1.C21mdk.i586.rpm
Mandrake Corporate Server 2.1
http://www.mandrakesecure.net/en/ftp.php -
Mandrake ksymoops-2.4.5-1.1.C21mdk.x86_64.rpm
Mandrake Corporate Server 2.1/X86_64
http://www.mandrakesecure.net/en/ftp.php
GNU Ksymoops 2.4.8
-
Mandrake ksymoops-2.4.8-1.1.91mdk.i586.rpm
Mandrake Linux 9.1
http://www.mandrakesecure.net/en/ftp.php -
Mandrake ksymoops-2.4.8-1.1.91mdk.ppc.rpm
Mandrake Linux 9.1/PPC
http://www.mandrakesecure.net/en/ftp.php
GNU Ksymoops 2.4.9
-
Mandrake ksymoops-2.4.9-2.1.100mdk.amd64.rpm
Mandrake Linux 10.0/AMD64
http://www.mandrakesecure.net/en/ftp.php -
Mandrake ksymoops-2.4.9-2.1.100mdk.i586.rpm
Mandrake Linux 10.0
http://www.mandrakesecure.net/en/ftp.php -
Mandrake ksymoops-2.4.9-2.1.92mdk.amd64.rpm
Mandrake Linux 9.2/AMD64
http://www.mandrakesecure.net/en/ftp.php -
Mandrake ksymoops-2.4.9-2.1.92mdk.i586.rpm
Mandrake Linux 9.2
http://www.mandrakesecure.net/en/ftp.php
References
KSymoops KSymoops-GZNM Insecure Temporary File Handling Symbolic Link Vulnerability
References:
References:
- Ksymoops Homepage (GNU)