CatDoc XLSView Local Insecure Temporary File Creation Vulnerability
BID:11560
Info
CatDoc XLSView Local Insecure Temporary File Creation Vulnerability
| Bugtraq ID: | 11560 |
| Class: | Design Error |
| CVE: |
CVE-2003-0193 |
| Remote: | No |
| Local: | Yes |
| Published: | Mar 05 2003 12:00AM |
| Updated: | Jul 12 2009 08:06AM |
| Credit: | The individual or individuals responsible for disclosure of this issue is currently unknown; these issues were disclosed in the referenced Debian advisory. |
| Vulnerable: |
Free Software Foundation CatDoc 0.91.5 |
| Not Vulnerable: | |
Discussion
CatDoc XLSView Local Insecure Temporary File Creation Vulnerability
catdoc xlsview is affected by a local insecure temporary file creation vulnerability. This issue is due to a design error that causes the application to fail to verify the existence of a temporary file prior to writing to it.
An attacker may leverage this issue to corrupt arbitrary files with the privileges of an unsuspecting user running the vulnerable application. It is possible that this issue may be leveraged to escalate privileges, although this is not confirmed.
catdoc xlsview is affected by a local insecure temporary file creation vulnerability. This issue is due to a design error that causes the application to fail to verify the existence of a temporary file prior to writing to it.
An attacker may leverage this issue to corrupt arbitrary files with the privileges of an unsuspecting user running the vulnerable application. It is possible that this issue may be leveraged to escalate privileges, although this is not confirmed.
Exploit / POC
CatDoc XLSView Local Insecure Temporary File Creation Vulnerability
No exploit is required to leverage this issue.
No exploit is required to leverage this issue.
Solution / Fix
CatDoc XLSView Local Insecure Temporary File Creation Vulnerability
Solution:
Debian Linux has released advisory DSA 575-1 along with fixes dealing with this issue. Please see the referenced advisory for more information.
Free Software Foundation CatDoc 0.91.5
Solution:
Debian Linux has released advisory DSA 575-1 along with fixes dealing with this issue. Please see the referenced advisory for more information.
Free Software Foundation CatDoc 0.91.5
-
Debian catdoc_0.91.5-1.woody3_alpha.deb
Debian GNU/Linux 3.0 alias woody
http://security.debian.org/pool/updates/main/c/catdoc/catdoc_0.91.5-1. woody3_alpha.deb -
Debian catdoc_0.91.5-1.woody3_hppa.deb
Debian GNU/Linux 3.0 alias woody
http://security.debian.org/pool/updates/main/c/catdoc/catdoc_0.91.5-1. woody3_hppa.deb -
Debian catdoc_0.91.5-1.woody3_i386.deb
Debian GNU/Linux 3.0 alias woody
http://security.debian.org/pool/updates/main/c/catdoc/catdoc_0.91.5-1. woody3_i386.deb -
Debian catdoc_0.91.5-1.woody3_ia64.deb
Debian GNU/Linux 3.0 alias woody
http://security.debian.org/pool/updates/main/c/catdoc/catdoc_0.91.5-1. woody3_ia64.deb -
Debian catdoc_0.91.5-1.woody3_m68k.deb
Debian GNU/Linux 3.0 alias woody
http://security.debian.org/pool/updates/main/c/catdoc/catdoc_0.91.5-1. woody3_m68k.deb -
Debian catdoc_0.91.5-1.woody3_mips.deb
Debian GNU/Linux 3.0 alias woody
http://security.debian.org/pool/updates/main/c/catdoc/catdoc_0.91.5-1. woody3_mips.deb -
Debian catdoc_0.91.5-1.woody3_mipsel.deb
Debian GNU/Linux 3.0 alias woody
http://security.debian.org/pool/updates/main/c/catdoc/catdoc_0.91.5-1. woody3_mipsel.deb -
Debian catdoc_0.91.5-1.woody3_powerpc.deb
Debian GNU/Linux 3.0 alias woody
http://security.debian.org/pool/updates/main/c/catdoc/catdoc_0.91.5-1. woody3_powerpc.deb -
Debian catdoc_0.91.5-1.woody3_s390.deb
Debian GNU/Linux 3.0 alias woody
http://security.debian.org/pool/updates/main/c/catdoc/catdoc_0.91.5-1. woody3_s390.deb -
Debian catdoc_0.91.5-1.woody3_sparc.deb
Debian GNU/Linux 3.0 alias woody
http://security.debian.org/pool/updates/main/c/catdoc/catdoc_0.91.5-1. woody3_sparc.deb
References
CatDoc XLSView Local Insecure Temporary File Creation Vulnerability
References:
References:
- catdoc Project Page (CatDoc)