Shorewall Insecure Temporary File Handling Symbolic Link Vulnerability
BID:10682
Info
Shorewall Insecure Temporary File Handling Symbolic Link Vulnerability
| Bugtraq ID: | 10682 |
| Class: | Access Validation Error |
| CVE: |
CVE-2004-0647 CVE-2004-0647 |
| Remote: | No |
| Local: | Yes |
| Published: | Jun 28 2004 12:00AM |
| Updated: | Jul 06 2016 12:19PM |
| Credit: | Discovery is credited to Javier Fernández-Sanguino. |
| Vulnerable: |
Shorewall Shorewall 2.0.3 Shorewall Shorewall 2.0.2 Shorewall Shorewall 2.0.1 Shorewall Shorewall 2.0 Shorewall Shorewall 1.4.10 Shorewall Shorewall 1.4.9 Shorewall Shorewall 1.4.8 Shorewall Shorewall 1.4.7 Shorewall Shorewall 1.4.6 Shorewall Shorewall 1.4.5 Shorewall Shorewall 1.4.4 Shorewall Shorewall 1.4.3 a Shorewall Shorewall 1.4.3 Shorewall Shorewall 1.4.2 Shorewall Shorewall 1.4.1 Shorewall Shorewall 1.4 Shorewall Shorewall 1.3.14 Shorewall Shorewall 1.3.11 Shorewall Shorewall 1.3.7 c Shorewall Shorewall 1.2.9 |
| Not Vulnerable: |
Shorewall Shorewall 2.0.3 a Shorewall Shorewall 2.0.3 Shorewall Shorewall 2.0.2 Shorewall Shorewall 2.0.1 Shorewall Shorewall 2.0 Shorewall Shorewall 1.4.10 f |
Discussion
Shorewall Insecure Temporary File Handling Symbolic Link Vulnerability
It is reported that Shorewall is prone to a local insecure temporary file handling symbolic link vulnerability. This issue is due to a design error that allows the application to insecurely handle temporary files and directories. This can facilitate a symbolic link attack.
An attacker may exploit this issue to corrupt arbitrary files. This corruption may potentially result in the elevation of privileges, or in a system wide denial of service.
It is reported that Shorewall is prone to a local insecure temporary file handling symbolic link vulnerability. This issue is due to a design error that allows the application to insecurely handle temporary files and directories. This can facilitate a symbolic link attack.
An attacker may exploit this issue to corrupt arbitrary files. This corruption may potentially result in the elevation of privileges, or in a system wide denial of service.
Exploit / POC
Shorewall Insecure Temporary File Handling Symbolic Link Vulnerability
Currently we are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Currently we are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution / Fix
Shorewall Insecure Temporary File Handling Symbolic Link Vulnerability
Solution:
The vendor has provided fixes for this issue.
Mandrake has released an advisory (MDKSA-2004:080) and fixes to address this issue. Please see the referenced advisory for further details regarding obtaining and applying appropriate fixes.
Gentoo has released an advisory (GLSA 200407-07) to address this issue. Please see the referenced advisory for more information. Gentoo users may carry out the following commands to update their computers:
emerge sync
emerge -pv ">=net-firewall/shorewall-1.4.10f"
emerge ">=net-firewall/shorewall-1.4.10f"
Shorewall Shorewall 1.3.14
Shorewall Shorewall 1.3.7 c
Shorewall Shorewall 1.4
Shorewall Shorewall 1.4.1
Shorewall Shorewall 1.4.10
Shorewall Shorewall 1.4.2
Shorewall Shorewall 1.4.3 a
Shorewall Shorewall 1.4.3
Shorewall Shorewall 1.4.4
Shorewall Shorewall 1.4.5
Shorewall Shorewall 1.4.6
Shorewall Shorewall 1.4.7
Shorewall Shorewall 1.4.8
Shorewall Shorewall 1.4.9
Shorewall Shorewall 2.0
Shorewall Shorewall 2.0.1
Shorewall Shorewall 2.0.2
Shorewall Shorewall 2.0.3
Solution:
The vendor has provided fixes for this issue.
Mandrake has released an advisory (MDKSA-2004:080) and fixes to address this issue. Please see the referenced advisory for further details regarding obtaining and applying appropriate fixes.
Gentoo has released an advisory (GLSA 200407-07) to address this issue. Please see the referenced advisory for more information. Gentoo users may carry out the following commands to update their computers:
emerge sync
emerge -pv ">=net-firewall/shorewall-1.4.10f"
emerge ">=net-firewall/shorewall-1.4.10f"
Shorewall Shorewall 1.3.14
-
Mandrake shorewall-1.3.14-3.1.91mdk.noarch.rpm
Mandrake Linux 9.1 & 9.1/PPC
http://www.mandrakesecure.net/en/ftp.php
Shorewall Shorewall 1.3.7 c
-
Mandrake shorewall-1.3.7c-1.1.C21mdk.noarch.rpm
Mandrake Corporate Server 2.1 & 2.1/x86_64
http://www.mandrakesecure.net/en/ftp.php -
Mandrake shorewall-doc-1.3.7c-1.1.C21mdk.noarch.rpm
Mandrake Corporate Server 2.1 & 2.1/x86_64
http://www.mandrakesecure.net/en/ftp.php
Shorewall Shorewall 1.4
-
Shorewall shorewall-1.4.10f
ftp://shorewall.net/pub/shorewall/shorewall-1.4.10f
Shorewall Shorewall 1.4.1
-
Shorewall shorewall-1.4.10f
ftp://shorewall.net/pub/shorewall/shorewall-1.4.10f
Shorewall Shorewall 1.4.10
-
Shorewall shorewall-1.4.10f
ftp://shorewall.net/pub/shorewall/shorewall-1.4.10f
Shorewall Shorewall 1.4.2
-
Shorewall shorewall-1.4.10f
ftp://shorewall.net/pub/shorewall/shorewall-1.4.10f
Shorewall Shorewall 1.4.3 a
-
Shorewall shorewall-1.4.10f
ftp://shorewall.net/pub/shorewall/shorewall-1.4.10f
Shorewall Shorewall 1.4.3
-
Shorewall shorewall-1.4.10f
ftp://shorewall.net/pub/shorewall/shorewall-1.4.10f
Shorewall Shorewall 1.4.4
-
Shorewall shorewall-1.4.10f
ftp://shorewall.net/pub/shorewall/shorewall-1.4.10f
Shorewall Shorewall 1.4.5
-
Shorewall shorewall-1.4.10f
ftp://shorewall.net/pub/shorewall/shorewall-1.4.10f
Shorewall Shorewall 1.4.6
-
Mandrake shorewall-1.4.8-2.2.92mdk.noarch.rpm
Mandrake Linux 9.2 & 9.2/AMD64
http://www.mandrakesecure.net/en/ftp.php -
Mandrake shorewall-doc-1.4.8-2.2.92mdk.noarch.rpm
Mandrake Linux 9.2 & 9.2/AMD64
http://www.mandrakesecure.net/en/ftp.php -
Shorewall shorewall-1.4.10f
ftp://shorewall.net/pub/shorewall/shorewall-1.4.10f
Shorewall Shorewall 1.4.7
-
Shorewall shorewall-1.4.10f
ftp://shorewall.net/pub/shorewall/shorewall-1.4.10f
Shorewall Shorewall 1.4.8
-
Mandrake shorewall-2.0.1-3.2.100mdk.noarch.rpm
Mandrake Linux 10.0 & 10.0/AMD64
http://www.mandrakesecure.net/en/ftp.php -
Mandrake shorewall-doc-2.0.1-3.2.100mdk.noarch.rpm
Mandrake Linux 10.0 & 10.0/AMD64
http://www.mandrakesecure.net/en/ftp.php -
Shorewall shorewall-1.4.10f
ftp://shorewall.net/pub/shorewall/shorewall-1.4.10f
Shorewall Shorewall 1.4.9
-
Shorewall shorewall-1.4.10f
ftp://shorewall.net/pub/shorewall/shorewall-1.4.10f
Shorewall Shorewall 2.0
-
Shorewall shorewall-2.0.3a
ftp://shorewall.net/pub/shorewall/shorewall-2.0.3a
Shorewall Shorewall 2.0.1
-
Shorewall shorewall-2.0.3a
ftp://shorewall.net/pub/shorewall/shorewall-2.0.3a
Shorewall Shorewall 2.0.2
-
Shorewall shorewall-2.0.3a
ftp://shorewall.net/pub/shorewall/shorewall-2.0.3a
Shorewall Shorewall 2.0.3
-
Shorewall shorewall-2.0.3a
ftp://shorewall.net/pub/shorewall/shorewall-2.0.3a
References
Shorewall Insecure Temporary File Handling Symbolic Link Vulnerability
References:
References:
- [Shorewall-announce] URGENT: Shorewall Security Vulnerability (Tom Eastep )
- Shorewall Homepage (Shorewall)