DGen Emulator Symbolic Link Vulnerability
BID:10855
Info
DGen Emulator Symbolic Link Vulnerability
| Bugtraq ID: | 10855 |
| Class: | Design Error |
| CVE: |
CVE-2004-0770 |
| Remote: | No |
| Local: | Yes |
| Published: | Aug 04 2004 12:00AM |
| Updated: | Jul 12 2009 06:16AM |
| Credit: | Discovery of this issue is credited to Joey Hess. |
| Vulnerable: |
DGen Emulator 1.23 DGen Emulator 1.22 DGen Emulator 1.21 DGen Emulator 1.20 a DGen Emulator 1.20 DGen Emulator 1.18 DGen Emulator 1.17 DGen Emulator 1.16 DGen Emulator 1.15 Debian Linux 3.0 sparc Debian Linux 3.0 s/390 Debian Linux 3.0 ppc Debian Linux 3.0 mipsel Debian Linux 3.0 mips Debian Linux 3.0 m68k Debian Linux 3.0 ia-64 Debian Linux 3.0 ia-32 Debian Linux 3.0 hppa Debian Linux 3.0 arm Debian Linux 3.0 alpha Debian Linux 3.0 |
| Not Vulnerable: | |
Discussion
DGen Emulator Symbolic Link Vulnerability
DGen is reportedly affected by a symbolic link vulnerability. This issue is due to a design error that fails to properly verify files prior to writing to them.
Successful exploitation of this issue will allow a local attacker to cause the affected application to overwrite arbitrary files with the privileges of the user that invoked the affected application. Reportedly this issue could be leveraged to facilitate privilege escalation.
DGen is reportedly affected by a symbolic link vulnerability. This issue is due to a design error that fails to properly verify files prior to writing to them.
Successful exploitation of this issue will allow a local attacker to cause the affected application to overwrite arbitrary files with the privileges of the user that invoked the affected application. Reportedly this issue could be leveraged to facilitate privilege escalation.
Exploit / POC
DGen Emulator Symbolic Link Vulnerability
No exploit is required to leverage this issue.
No exploit is required to leverage this issue.
Solution / Fix
DGen Emulator Symbolic Link Vulnerability
Solution:
Debian GNU/Linux has released fixed packages. Users of affected packages are urged to utilize Debian's package management software to install version 1.23-6 or later of 'dgen'.
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution:
Debian GNU/Linux has released fixed packages. Users of affected packages are urged to utilize Debian's package management software to install version 1.23-6 or later of 'dgen'.
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
References
DGen Emulator Symbolic Link Vulnerability
References:
References:
- Debian Bug report logs - #263282 - insecure temp files (Debian)
- DGen Home Page (DGen)