Gentoo MirrorSelect Local Insecure File Creation Vulnerability
BID:11835
Info
Gentoo MirrorSelect Local Insecure File Creation Vulnerability
| Bugtraq ID: | 11835 |
| Class: | Design Error |
| CVE: | |
| Remote: | No |
| Local: | Yes |
| Published: | Dec 07 2004 12:00AM |
| Updated: | Dec 07 2004 12:00AM |
| Credit: | Ervin Nemeth is credited with the discovery of this issue. |
| Vulnerable: |
Gentoo mirrorselect 0.88 Gentoo mirrorselect 0.87 Gentoo mirrorselect 0.86 Gentoo mirrorselect 0.85 Gentoo mirrorselect 0.84 Gentoo mirrorselect 0.83 Gentoo mirrorselect 0.82 Gentoo mirrorselect 0.81 Gentoo mirrorselect 0.80 |
| Not Vulnerable: |
Gentoo mirrorselect 0.89 |
Discussion
Gentoo MirrorSelect Local Insecure File Creation Vulnerability
A local insecure file creation vulnerability affects Gentoo mirrorselect. This issue is likely due to a design error that causes the application to fail to verify the existence of a file before writing to it.
An attacker may leverage this issue to overwrite arbitrary files with the privileges of an unsuspecting user that activates the vulnerable utility.
A local insecure file creation vulnerability affects Gentoo mirrorselect. This issue is likely due to a design error that causes the application to fail to verify the existence of a file before writing to it.
An attacker may leverage this issue to overwrite arbitrary files with the privileges of an unsuspecting user that activates the vulnerable utility.
Exploit / POC
Gentoo MirrorSelect Local Insecure File Creation Vulnerability
No exploit is required to leverage this issue.
No exploit is required to leverage this issue.
Solution / Fix
Gentoo MirrorSelect Local Insecure File Creation Vulnerability
Solution:
Gentoo Linux has released advisory GLSA 200412-05 along with fixes dealing with this issue. All mirrorselect users should upgrade to the latest version:
# emerge --sync
# emerge --ask --oneshot --verbose ">=app-portage/mirrorselect-0.89"
Please see the referenced Gentoo Linux advisory for more information.
Solution:
Gentoo Linux has released advisory GLSA 200412-05 along with fixes dealing with this issue. All mirrorselect users should upgrade to the latest version:
# emerge --sync
# emerge --ask --oneshot --verbose ">=app-portage/mirrorselect-0.89"
Please see the referenced Gentoo Linux advisory for more information.
References
Gentoo MirrorSelect Local Insecure File Creation Vulnerability
References:
References:
- Gentoo mirrorselect Portage Page (Gentoo)