CPlay Insecure Temporary File Handling Symbolic Link Vulnerability
BID:10597
Info
CPlay Insecure Temporary File Handling Symbolic Link Vulnerability
| Bugtraq ID: | 10597 |
| Class: | Access Validation Error |
| CVE: | |
| Remote: | No |
| Local: | Yes |
| Published: | Jun 23 2004 12:00AM |
| Updated: | Jun 23 2004 12:00AM |
| Credit: | Discovery of this vulnerability is credited to Martin Michlmayr. |
| Vulnerable: |
cplay cplay 1.49 |
| Not Vulnerable: | |
Discussion
CPlay Insecure Temporary File Handling Symbolic Link Vulnerability
It is reported that cplay is prone to a local insecure temporary file handling symbolic link vulnerability. This issue is due to a design error that allows the application to insecurely write to a temporary file that is created with a predictable file name. The cplay utility will write to this file before verifying its existence; this would facilitate a symbolic link attack.
It is reported that cplay is prone to a local insecure temporary file handling symbolic link vulnerability. This issue is due to a design error that allows the application to insecurely write to a temporary file that is created with a predictable file name. The cplay utility will write to this file before verifying its existence; this would facilitate a symbolic link attack.
Exploit / POC
CPlay Insecure Temporary File Handling Symbolic Link Vulnerability
Currently we are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Currently we are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution / Fix
CPlay Insecure Temporary File Handling Symbolic Link Vulnerability
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
References
CPlay Insecure Temporary File Handling Symbolic Link Vulnerability
References:
References:
- cplay Homepage (cplay)