MTink Insecure Temporary File Creation Vulnerability
BID:11640
Info
MTink Insecure Temporary File Creation Vulnerability
| Bugtraq ID: | 11640 |
| Class: | Access Validation Error |
| CVE: | |
| Remote: | No |
| Local: | Yes |
| Published: | Nov 09 2004 12:00AM |
| Updated: | Nov 09 2004 12:00AM |
| Credit: | Tavis Ormandy from Gentoo Linux discovered this vulnerability. |
| Vulnerable: |
Jean-Jacques Sarton mtink 1.0.4 Jean-Jacques Sarton mtink 0.9.53 Jean-Jacques Sarton mtink 0.9.52 Jean-Jacques Sarton mtink 0.9.33 Jean-Jacques Sarton mtink 0.9.32 Gentoo Linux |
| Not Vulnerable: |
Jean-Jacques Sarton mtink 1.0.5 |
Discussion
MTink Insecure Temporary File Creation Vulnerability
The MTink package is affected by an unspecified insecure temporary file creation vulnerability. This issue is likely due to a design error that causes the application to fail to verify the existence of a file before writing to it.
An attacker may leverage this issue to overwrite arbitrary files with the privileges of an unsuspecting user that activates the vulnerable application.
The MTink package is affected by an unspecified insecure temporary file creation vulnerability. This issue is likely due to a design error that causes the application to fail to verify the existence of a file before writing to it.
An attacker may leverage this issue to overwrite arbitrary files with the privileges of an unsuspecting user that activates the vulnerable application.
Exploit / POC
MTink Insecure Temporary File Creation Vulnerability
No exploit is required.
No exploit is required.
Solution / Fix
MTink Insecure Temporary File Creation Vulnerability
Solution:
This vulnerability has reportedly been fixed in version 1.0.5.
Gentoo Linux has released advisory GLSA 200411-17 dealing with this issue. Users of affected packages are urged to execute the following commands with superuser privileges:
emerge --sync
emerge --ask --oneshot --verbose ">=net-print/mtink-1.0.5"
Please see the referenced advisory for further information.
Jean-Jacques Sarton mtink 0.9.32
Jean-Jacques Sarton mtink 0.9.33
Jean-Jacques Sarton mtink 0.9.52
Jean-Jacques Sarton mtink 0.9.53
Jean-Jacques Sarton mtink 1.0.4
Solution:
This vulnerability has reportedly been fixed in version 1.0.5.
Gentoo Linux has released advisory GLSA 200411-17 dealing with this issue. Users of affected packages are urged to execute the following commands with superuser privileges:
emerge --sync
emerge --ask --oneshot --verbose ">=net-print/mtink-1.0.5"
Please see the referenced advisory for further information.
Jean-Jacques Sarton mtink 0.9.32
-
Jean-Jacques Sarton mtink-1.0.5.tar.gz
http://xwtools.automatix.de/files/mtink-1.0.5.tar.gz
Jean-Jacques Sarton mtink 0.9.33
-
Jean-Jacques Sarton mtink-1.0.5.tar.gz
http://xwtools.automatix.de/files/mtink-1.0.5.tar.gz
Jean-Jacques Sarton mtink 0.9.52
-
Jean-Jacques Sarton mtink-1.0.5.tar.gz
http://xwtools.automatix.de/files/mtink-1.0.5.tar.gz
Jean-Jacques Sarton mtink 0.9.53
-
Jean-Jacques Sarton mtink-1.0.5.tar.gz
http://xwtools.automatix.de/files/mtink-1.0.5.tar.gz
Jean-Jacques Sarton mtink 1.0.4
-
Jean-Jacques Sarton mtink-1.0.5.tar.gz
http://xwtools.automatix.de/files/mtink-1.0.5.tar.gz
References
MTink Insecure Temporary File Creation Vulnerability
References:
References:
- MTink Home Page (Jean-Jacques Sarton)