Davfs2 Insecure Temporary File Creation Vulnerability
BID:11661
Info
Davfs2 Insecure Temporary File Creation Vulnerability
| Bugtraq ID: | 11661 |
| Class: | Design Error |
| CVE: | |
| Remote: | No |
| Local: | Yes |
| Published: | Nov 11 2004 12:00AM |
| Updated: | Nov 11 2004 12:00AM |
| Credit: | Florian Schilhabel from the Gentoo Linux Security Audit Team discovered this vulnerability. |
| Vulnerable: |
Gentoo Linux Davfs Davfs2 0.2.2 Davfs Davfs2 0.2.1 Davfs Davfs2 0.2 .0 |
| Not Vulnerable: |
Davfs Davfs2 0.2.3 |
Discussion
Davfs2 Insecure Temporary File Creation Vulnerability
Davfs2 is affected by an insecure temporary file creation vulnerability. This issue is likely due to a design error that causes the application to fail to verify a files existence before writing to it.
An attacker may leverage this issue to overwrite arbitrary files with the privileges of an unsuspecting user that activates the vulnerable application.
Davfs2 is affected by an insecure temporary file creation vulnerability. This issue is likely due to a design error that causes the application to fail to verify a files existence before writing to it.
An attacker may leverage this issue to overwrite arbitrary files with the privileges of an unsuspecting user that activates the vulnerable application.
Exploit / POC
Davfs2 Insecure Temporary File Creation Vulnerability
An exploit is not required.
An exploit is not required.
Solution / Fix
Davfs2 Insecure Temporary File Creation Vulnerability
Solution:
The vendor has released version 0.2.3 of the affected package to address this issue.
Gentoo Linux has released advisory GLSA 200411-22 to address this issue. Users of affected packages are urged to execute the following commands with superuser privileges:
emerge --sync
emerge --ask --oneshot --verbose ">=net-fs/davfs2-0.2.2-r1"
Please see the referenced advisory for further information.
Davfs Davfs2 0.2 .0
Davfs Davfs2 0.2.1
Davfs Davfs2 0.2.2
Solution:
The vendor has released version 0.2.3 of the affected package to address this issue.
Gentoo Linux has released advisory GLSA 200411-22 to address this issue. Users of affected packages are urged to execute the following commands with superuser privileges:
emerge --sync
emerge --ask --oneshot --verbose ">=net-fs/davfs2-0.2.2-r1"
Please see the referenced advisory for further information.
Davfs Davfs2 0.2 .0
-
Davfs davfs2-0.2.3.tar.gz
http://prdownloads.sourceforge.net/dav/davfs2-0.2.3.tar.gz?download
Davfs Davfs2 0.2.1
-
Davfs davfs2-0.2.3.tar.gz
http://prdownloads.sourceforge.net/dav/davfs2-0.2.3.tar.gz?download
Davfs Davfs2 0.2.2
-
Davfs davfs2-0.2.3.tar.gz
http://prdownloads.sourceforge.net/dav/davfs2-0.2.3.tar.gz?download
References
Davfs2 Insecure Temporary File Creation Vulnerability
References:
References:
- 0.2.3 Release Notes (Davfs)
- Davfs2 ChangeLog (Davfs)
- Davfs2 Home Page (Davfs)