Gentoo Portage Dispatch-Conf Insecure Temporary File Creation Vulnerability
BID:11616
Info
Gentoo Portage Dispatch-Conf Insecure Temporary File Creation Vulnerability
| Bugtraq ID: | 11616 |
| Class: | Access Validation Error |
| CVE: | |
| Remote: | No |
| Local: | Yes |
| Published: | Nov 07 2004 12:00AM |
| Updated: | Nov 07 2004 12:00AM |
| Credit: | The vendor announced this vulnerability. |
| Vulnerable: |
Gentoo Linux |
| Not Vulnerable: | |
Discussion
Gentoo Portage Dispatch-Conf Insecure Temporary File Creation Vulnerability
The Gentoo dispatch-conf script is affected by an unspecified insecure temporary file creation vulnerability. This issue is likely due to a design error that causes the application to fail to verify the existence of a file before writing to it.
An attacker may leverage this issue to overwrite arbitrary files with the privileges of an unsuspecting user that activates the vulnerable application.
The Gentoo dispatch-conf script is affected by an unspecified insecure temporary file creation vulnerability. This issue is likely due to a design error that causes the application to fail to verify the existence of a file before writing to it.
An attacker may leverage this issue to overwrite arbitrary files with the privileges of an unsuspecting user that activates the vulnerable application.
Exploit / POC
Gentoo Portage Dispatch-Conf Insecure Temporary File Creation Vulnerability
No exploit is required.
No exploit is required.
Solution / Fix
Gentoo Portage Dispatch-Conf Insecure Temporary File Creation Vulnerability
Solution:
Gentoo Linux has released advisory GLSA 200411-13:01 to address this issue in dispatch-conf and other issues. Users of the affected package are urged to execute the following commands with superuser privileges to install the updates:
emerge --sync
emerge --ask --oneshot --verbose ">=sys-apps/portage-2.0.51-r3"
Solution:
Gentoo Linux has released advisory GLSA 200411-13:01 to address this issue in dispatch-conf and other issues. Users of the affected package are urged to execute the following commands with superuser privileges to install the updates:
emerge --sync
emerge --ask --oneshot --verbose ">=sys-apps/portage-2.0.51-r3"
References
Gentoo Portage Dispatch-Conf Insecure Temporary File Creation Vulnerability
References:
References: