IglooFTP File Upload Insecure Temporary File Vulnerability
BID:11961
Info
IglooFTP File Upload Insecure Temporary File Vulnerability
| Bugtraq ID: | 11961 |
| Class: | Access Validation Error |
| CVE: | |
| Remote: | No |
| Local: | Yes |
| Published: | Dec 15 2004 12:00AM |
| Updated: | Dec 15 2004 12:00AM |
| Credit: | Discovery is credited to Manigandan Radhakrishnan. |
| Vulnerable: |
IglooFTP IglooFTP 0.6.1 |
| Not Vulnerable: | |
Discussion
IglooFTP File Upload Insecure Temporary File Vulnerability
IglooFTP creates temporary files in an insecure manner. This issue is reported to occur when the client is uploading files to a remote server. An attacker could abuse this issue through symbolic link attacks that corrupt files owned by the user, most likely resulting in a loss of data.
This issue reportedly exists in UNIX/Linux based versions of IglooFTP. It is not known if Windows versions are affected.
IglooFTP creates temporary files in an insecure manner. This issue is reported to occur when the client is uploading files to a remote server. An attacker could abuse this issue through symbolic link attacks that corrupt files owned by the user, most likely resulting in a loss of data.
This issue reportedly exists in UNIX/Linux based versions of IglooFTP. It is not known if Windows versions are affected.
Exploit / POC
IglooFTP File Upload Insecure Temporary File Vulnerability
Currently we are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Currently we are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution / Fix
IglooFTP File Upload Insecure Temporary File Vulnerability
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
References
IglooFTP File Upload Insecure Temporary File Vulnerability
References:
References:
- [local] [control] IglooFTP 0.6.1 uses fopen in /tmp ("D. J. Bernstein"
) - IglooFTP Homepage (IglooFTP)