Cscope Insecure Temporary File Creation Vulnerabilities
BID:11697
Info
Cscope Insecure Temporary File Creation Vulnerabilities
| Bugtraq ID: | 11697 |
| Class: | Design Error |
| CVE: |
CVE-2004-0996 |
| Remote: | No |
| Local: | Yes |
| Published: | Nov 17 2004 12:00AM |
| Updated: | Aug 02 2007 05:25PM |
| Credit: | Gangstuck / Psirac <[email protected]> disclosed this vulnerability. Jeremy Bae from STG Security Inc <[email protected]> also disclosed this vulnerability to the vendor. |
| Vulnerable: |
SCO Unixware 7.1.4 SCO Unixware 7.1.3 SCO Unixware 7.1.1 Gentoo Linux Debian Linux 3.0 sparc Debian Linux 3.0 s/390 Debian Linux 3.0 ppc Debian Linux 3.0 mipsel Debian Linux 3.0 mips Debian Linux 3.0 m68k Debian Linux 3.0 ia-64 Debian Linux 3.0 ia-32 Debian Linux 3.0 hppa Debian Linux 3.0 arm Debian Linux 3.0 alpha Debian Linux 3.0 Cscope Cscope 15.5 Cscope Cscope 15.4 Cscope Cscope 15.3 Cscope Cscope 15.1 Cscope Cscope 13.0 Apple Mac OS X Server 10.4.10 Apple Mac OS X Server 10.3.9 Apple Mac OS X 10.4.10 Apple Mac OS X 10.3.9 |
| Not Vulnerable: | |
Discussion
Cscope Insecure Temporary File Creation Vulnerabilities
Cscope creates temporary files in an insecure way. A design error causes the application to fail to verify the presence of a file before writing to it.
During execution, the utility reportedly creates temporary files in the system's temporary directory, '/tmp', with predictable names. This allows attackers to create malicious symbolic links that Cscope will write to when an unsuspecting user executes it.
Attackers may leverage these issues to overwrite arbitrary files with the privileges of an unsuspecting user that activates the vulnerable application.
Versions up to and including Cscope 15.5 are reported vulnerable.
Cscope creates temporary files in an insecure way. A design error causes the application to fail to verify the presence of a file before writing to it.
During execution, the utility reportedly creates temporary files in the system's temporary directory, '/tmp', with predictable names. This allows attackers to create malicious symbolic links that Cscope will write to when an unsuspecting user executes it.
Attackers may leverage these issues to overwrite arbitrary files with the privileges of an unsuspecting user that activates the vulnerable application.
Versions up to and including Cscope 15.5 are reported vulnerable.
Exploit / POC
Cscope Insecure Temporary File Creation Vulnerabilities
Although an exploit is not required, example programs have been provided:
Although an exploit is not required, example programs have been provided:
Solution / Fix
Cscope Insecure Temporary File Creation Vulnerabilities
Solution:
Please see the referenced advisories for more information.
Apple Mac OS X 10.3.9
Apple Mac OS X Server 10.3.9
Apple Mac OS X 10.4.10
Apple Mac OS X Server 10.4.10
Cscope Cscope 15.3
SCO Unixware 7.1.1
SCO Unixware 7.1.3
SCO Unixware 7.1.4
Solution:
Please see the referenced advisories for more information.
Apple Mac OS X 10.3.9
-
Apple SecUpd2007-007Pan.dmg For Mac OS X v10.3.9
http://www.apple.com/support/downloads/
Apple Mac OS X Server 10.3.9
-
Apple SecUpdSrvr2007-007Pan.dmg For Mac OS X Server v10.3.9
http://www.apple.com/support/downloads/
Apple Mac OS X 10.4.10
-
Apple SecUpd2007-007Ti.dmg For Mac OS X v10.4.10 (PowerPC)
http://www.apple.com/support/downloads/ -
Apple SecUpd2007-007Univ.dmg For Mac OS X v10.4.10 (Universal)
http://www.apple.com/support/downloads/
Apple Mac OS X Server 10.4.10
-
Apple SecUpdSrvr2007-007Ti.dmg For Mac OS X Server v10.4.10 (PowerPC)
http://www.apple.com/support/downloads/ -
Apple SecUpdSrvr2007-007Universal.dmg For Mac OS X Server v10.4.10 (Universal)
http://www.apple.com/support/downloads/
Cscope Cscope 15.3
-
Debian cscope_15.3-1woody2_alpha.deb
Debian GNU/Linux 3.0 alias woody
http://security.debian.org/pool/updates/main/c/cscope/cscope_15.3-1woo dy2_alpha.deb -
Debian cscope_15.3-1woody2_arm.deb
Debian GNU/Linux 3.0 alias woody
http://security.debian.org/pool/updates/main/c/cscope/cscope_15.3-1woo dy2_arm.deb -
Debian cscope_15.3-1woody2_hppa.deb
Debian GNU/Linux 3.0 alias woody
http://security.debian.org/pool/updates/main/c/cscope/cscope_15.3-1woo dy2_hppa.deb -
Debian cscope_15.3-1woody2_i386.deb
Debian GNU/Linux 3.0 alias woody
http://security.debian.org/pool/updates/main/c/cscope/cscope_15.3-1woo dy2_i386.deb -
Debian cscope_15.3-1woody2_ia64.deb
Debian GNU/Linux 3.0 alias woody
http://security.debian.org/pool/updates/main/c/cscope/cscope_15.3-1woo dy2_ia64.deb -
Debian cscope_15.3-1woody2_m68k.deb
Debian GNU/Linux 3.0 alias woody
http://security.debian.org/pool/updates/main/c/cscope/cscope_15.3-1woo dy2_m68k.deb -
Debian cscope_15.3-1woody2_mips.deb
Debian GNU/Linux 3.0 alias woody
http://security.debian.org/pool/updates/main/c/cscope/cscope_15.3-1woo dy2_mips.deb -
Debian cscope_15.3-1woody2_mipsel.deb
Debian GNU/Linux 3.0 alias woody
http://security.debian.org/pool/updates/main/c/cscope/cscope_15.3-1woo dy2_mipsel.deb -
Debian cscope_15.3-1woody2_powerpc.deb
Debian GNU/Linux 3.0 alias woody
http://security.debian.org/pool/updates/main/c/cscope/cscope_15.3-1woo dy2_powerpc.deb -
Debian cscope_15.3-1woody2_s390.deb
Debian GNU/Linux 3.0 alias woody
http://security.debian.org/pool/updates/main/c/cscope/cscope_15.3-1woo dy2_s390.deb -
Debian cscope_15.3-1woody2_sparc.deb
Debian GNU/Linux 3.0 alias woody
http://security.debian.org/pool/updates/main/c/cscope/cscope_15.3-1woo dy2_sparc.deb
SCO Unixware 7.1.1
-
SCO erg712738.pkg.Z
ftp://ftp.sco.com/pub/updates/UnixWare/SCOSA-2004.21/erg712738.pkg.Z
SCO Unixware 7.1.3
-
SCO erg712738.pkg.Z
ftp://ftp.sco.com/pub/updates/UnixWare/SCOSA-2004.21/erg712738.pkg.Z
SCO Unixware 7.1.4
-
SCO erg712738.pkg.Z
ftp://ftp.sco.com/pub/updates/UnixWare/SCOSA-2004.21/erg712738.pkg.Z
References
Cscope Insecure Temporary File Creation Vulnerabilities
References:
References:
- [ 1062807 ] Insecure temp file creation vulnerability (Cscope)
- Cscope Home Page (Cscope)
- Re: RX171104 Cscope v15.5 and minors - symlink vulnerability - advisory, exploi (Hans-Bernhard Broeker
) - Re: RX171104 Cscope v15.5 and minors - symlink vulnerability - advisory, exploi (rexolab
) - RX171104 Cscope v15.5 and minors - symlink vulnerability - advisory, exploit an (rexolab
) - STG Security Advisory: [SSA-20041122-09] cscope insecure temp file creation (
)