Esearch eupdatedb Symbolic Link Vulnerability
BID:10644
Info
Esearch eupdatedb Symbolic Link Vulnerability
| Bugtraq ID: | 10644 |
| Class: | Design Error |
| CVE: |
CVE-2004-0655 |
| Remote: | No |
| Local: | Yes |
| Published: | Jul 01 2004 12:00AM |
| Updated: | Jul 12 2009 05:16AM |
| Credit: | The individual responsible for the discovery of this issue is currently unknown; this issue was disclosed in the referenced Gentoo advisory. |
| Vulnerable: |
esearch emerge search tool 0.6.1 esearch emerge search tool 0.6 esearch emerge search tool 0.5.3 esearch emerge search tool 0.5.2 esearch emerge search tool 0.5.1 esearch emerge search tool 0.5 esearch emerge search tool 0.4.2 esearch emerge search tool 0.4.1 esearch emerge search tool 0.4 esearch emerge search tool 0.3.1 |
| Not Vulnerable: |
esearch emerge search tool 0.6.2 |
Discussion
Esearch eupdatedb Symbolic Link Vulnerability
It has been reported that eupdatedb, an esearch utility is affected by a symbolic link vulnerability. This issue is due to a failure of the application to properly handle temporary file creation.
An attacker can leverage this vulnerability to create an arbitrary file with the permissions of an unsuspecting user that has activated the vulnerable utility; facilitating a number of possible attacks.
It has been reported that eupdatedb, an esearch utility is affected by a symbolic link vulnerability. This issue is due to a failure of the application to properly handle temporary file creation.
An attacker can leverage this vulnerability to create an arbitrary file with the permissions of an unsuspecting user that has activated the vulnerable utility; facilitating a number of possible attacks.
Exploit / POC
Esearch eupdatedb Symbolic Link Vulnerability
No exploit is required to leverage this issue.
No exploit is required to leverage this issue.
Solution / Fix
Esearch eupdatedb Symbolic Link Vulnerability
Solution:
Gentoo has released advisory GLSA 200407-01 along with an upgrade dealing with this issue. Gentoo has advised the following actions be taken to apply the upgrade:
# emerge sync
# emerge -pv ">=app-portage/esearch-0.6.2"
# emerge ">=app-portage/esearch-0.6.2"
Please see the referenced advisory for more information.
Solution:
Gentoo has released advisory GLSA 200407-01 along with an upgrade dealing with this issue. Gentoo has advised the following actions be taken to apply the upgrade:
# emerge sync
# emerge -pv ">=app-portage/esearch-0.6.2"
# emerge ">=app-portage/esearch-0.6.2"
Please see the referenced advisory for more information.