Gentoo Gentoolkit QPKG Insecure Temporary File Creation Vulnerability
BID:11617
Info
Gentoo Gentoolkit QPKG Insecure Temporary File Creation Vulnerability
| Bugtraq ID: | 11617 |
| Class: | Access Validation Error |
| CVE: | |
| Remote: | No |
| Local: | Yes |
| Published: | Nov 07 2004 12:00AM |
| Updated: | Nov 07 2004 12:00AM |
| Credit: | The vendor announced this vulnerability. |
| Vulnerable: |
Gentoo Linux |
| Not Vulnerable: | |
Discussion
Gentoo Gentoolkit QPKG Insecure Temporary File Creation Vulnerability
The qpkg utility is affected by an unspecified insecure temporary file creation vulnerability. This issue is likely due to a design error that causes the application to fail to verify the existence of a file before writing to it.
An attacker may leverage this issue to overwrite arbitrary files with the privileges of an unsuspecting user that activates the vulnerable application.
The qpkg utility is affected by an unspecified insecure temporary file creation vulnerability. This issue is likely due to a design error that causes the application to fail to verify the existence of a file before writing to it.
An attacker may leverage this issue to overwrite arbitrary files with the privileges of an unsuspecting user that activates the vulnerable application.
Exploit / POC
Gentoo Gentoolkit QPKG Insecure Temporary File Creation Vulnerability
No exploit is required.
No exploit is required.
Solution / Fix
Gentoo Gentoolkit QPKG Insecure Temporary File Creation Vulnerability
Solution:
Gentoo Linux has released advisory GLSA 200411-13:01 to address this issue in qpkg and other issues. Users of the affected package are urged to execute the following commands with superuser privileges to install the updates:
emerge --sync
emerge --ask --oneshot --verbose ">=app-portage/gentoolkit-0.2.0_pre8-r1"
Solution:
Gentoo Linux has released advisory GLSA 200411-13:01 to address this issue in qpkg and other issues. Users of the affected package are urged to execute the following commands with superuser privileges to install the updates:
emerge --sync
emerge --ask --oneshot --verbose ">=app-portage/gentoolkit-0.2.0_pre8-r1"
References
Gentoo Gentoolkit QPKG Insecure Temporary File Creation Vulnerability
References:
References: