Zinf/Freeamp Unspecified Insecure Temporary File Creation Vulnerability
BID:11490
Info
Zinf/Freeamp Unspecified Insecure Temporary File Creation Vulnerability
| Bugtraq ID: | 11490 |
| Class: | Access Validation Error |
| CVE: | |
| Remote: | No |
| Local: | Yes |
| Published: | Oct 21 2004 12:00AM |
| Updated: | Oct 21 2004 12:00AM |
| Credit: | This vulnerability was announced in a SuSE advisory. |
| Vulnerable: |
Zinf Zinf 2.2.1 S.u.S.E. Linux Personal 9.1 Freeamp Freeamp 6.0 2.1.1 |
| Not Vulnerable: | |
Discussion
Zinf/Freeamp Unspecified Insecure Temporary File Creation Vulnerability
Zinf/Freeamp are affected by an unspecified insecure temporary file creation vulnerability. This issue is likely due to a design error that causes the application to fail to verify the existence of a file before writing to it.
An attacker may leverage this issue to overwrite arbitrary files with the privileges of an unsuspecting user that activates the vulnerable application.
Zinf/Freeamp are affected by an unspecified insecure temporary file creation vulnerability. This issue is likely due to a design error that causes the application to fail to verify the existence of a file before writing to it.
An attacker may leverage this issue to overwrite arbitrary files with the privileges of an unsuspecting user that activates the vulnerable application.
Exploit / POC
Zinf/Freeamp Unspecified Insecure Temporary File Creation Vulnerability
Currently we are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Currently we are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution / Fix
Zinf/Freeamp Unspecified Insecure Temporary File Creation Vulnerability
Solution:
SuSE has released advisory SUSE-SA:2004:037 mainly to address the vulnerabilities described in BID 11488 and 11489. However, in the addendum of this advisory, it is reported that fixes for the issue described in this BID are now available on the SuSE update FTP server for download. Customers are advised to see the referenced advisory for further information regarding obtaining and applying appropriate updates.
Zinf Zinf 2.2.1
Solution:
SuSE has released advisory SUSE-SA:2004:037 mainly to address the vulnerabilities described in BID 11488 and 11489. However, in the addendum of this advisory, it is reported that fixes for the issue described in this BID are now available on the SuSE update FTP server for download. Customers are advised to see the referenced advisory for further information regarding obtaining and applying appropriate updates.
Zinf Zinf 2.2.1
-
SuSE zinf-2.2.4-150.i586.rpm
ftp://ftp.suse.com/pub/suse/i386/update/9.0/rpm/i586/zinf-2.2.4-150.i5 86.rpm -
SuSE zinf-2.2.4-150.x86_64.rpm
ftp://ftp.suse.com/pub/suse/x86_64/update/9.0/rpm/x86_64/zinf-2.2.4-15 0.x86_64.rpm
References
Zinf/Freeamp Unspecified Insecure Temporary File Creation Vulnerability
References:
References:
- Freeamp Homepage (Freeamp)
- Zinf Homepage (Zinf)