Apache Utilities Insecure Temporary File Creation Vulnerability
BID:12308
Info
Apache Utilities Insecure Temporary File Creation Vulnerability
| Bugtraq ID: | 12308 |
| Class: | Design Error |
| CVE: | |
| Remote: | No |
| Local: | Yes |
| Published: | Jan 19 2005 12:00AM |
| Updated: | Jan 19 2005 12:00AM |
| Credit: | Javier Fernández-Sanguino Peña is credited with the discovery of this issue. |
| Vulnerable: |
Apache Apache 1.3.33 Apache Apache 1.3.32 Apache Apache 1.3.31 Apache Apache 1.3.29 Apache Apache 1.3.28 Apache Apache 1.3.27 Apache Apache 1.3.26 Apache Apache 1.3.25 Apache Apache 1.3.24 Apache Apache 1.3.23 Apache Apache 1.3.22 Apache Apache 1.3.20 Apache Apache 1.3.19 Apache Apache 1.3.18 Apache Apache 1.3.17 Apache Apache 1.3.14 Apache Apache 1.3.12 Apache Apache 1.3.11 Apache Apache 1.3.9 Apache Apache 1.3.7 -dev Apache Apache 1.3.6 Apache Apache 1.3.4 Apache Apache 1.3.3 Apache Apache 1.3.1 Apache Apache 1.3 |
| Not Vulnerable: | |
Discussion
Apache Utilities Insecure Temporary File Creation Vulnerability
A local insecure temporary file creation vulnerability reportedly affects Apache Software Foundation Apache Utilities. This issue is due to a failure of the affected utility to securely create temporary files in world writable locations.
An attacker may leverage this issue to corrupt, write to or create arbitrary files with the privileges of the user or process running the vulnerable script.
A local insecure temporary file creation vulnerability reportedly affects Apache Software Foundation Apache Utilities. This issue is due to a failure of the affected utility to securely create temporary files in world writable locations.
An attacker may leverage this issue to corrupt, write to or create arbitrary files with the privileges of the user or process running the vulnerable script.
Exploit / POC
Apache Utilities Insecure Temporary File Creation Vulnerability
No exploit is required to leverage this issue.
No exploit is required to leverage this issue.
Solution / Fix
Apache Utilities Insecure Temporary File Creation Vulnerability
Solution:
Ubuntu Linux has made advisory USN-65-1 along with fixes available dealing with this issue. Please see the referenced advisory for more information.
Apache Apache 1.3.31
Solution:
Ubuntu Linux has made advisory USN-65-1 along with fixes available dealing with this issue. Please see the referenced advisory for more information.
Apache Apache 1.3.31
-
Ubuntu apache-common_1.3.31-6ubuntu0.4_amd64.deb
Ubuntu 4.10 (Warty Warthog)
http://security.ubuntu.com/ubuntu/pool/main/a/apache/apache-common_1.3 .31-6ubuntu0.4_amd64.deb -
Ubuntu apache-common_1.3.31-6ubuntu0.4_i386.deb
Ubuntu 4.10 (Warty Warthog)
http://security.ubuntu.com/ubuntu/pool/main/a/apache/apache-common_1.3 .31-6ubuntu0.4_i386.deb -
Ubuntu apache-common_1.3.31-6ubuntu0.4_powerpc.deb
Ubuntu 4.10 (Warty Warthog)
http://security.ubuntu.com/ubuntu/pool/main/a/apache/apache-common_1.3 .31-6ubuntu0.4_powerpc.deb -
Ubuntu apache-dbg_1.3.31-6ubuntu0.4_amd64.deb
Ubuntu 4.10 (Warty Warthog)
http://security.ubuntu.com/ubuntu/pool/universe/a/apache/apache-dbg_1. 3.31-6ubuntu0.4_amd64.deb -
Ubuntu apache-dbg_1.3.31-6ubuntu0.4_i386.deb
Ubuntu 4.10 (Warty Warthog)
http://security.ubuntu.com/ubuntu/pool/universe/a/apache/apache-dbg_1. 3.31-6ubuntu0.4_i386.deb -
Ubuntu apache-dbg_1.3.31-6ubuntu0.4_powerpc.deb
Ubuntu 4.10 (Warty Warthog)
http://security.ubuntu.com/ubuntu/pool/universe/a/apache/apache-dbg_1. 3.31-6ubuntu0.4_powerpc.deb -
Ubuntu apache-dev_1.3.31-6ubuntu0.4_all.deb
Ubuntu 4.10 (Warty Warthog)
http://security.ubuntu.com/ubuntu/pool/main/a/apache/apache-dev_1.3.31 -6ubuntu0.4_all.deb -
Ubuntu apache-doc_1.3.31-6ubuntu0.4_all.deb
Ubuntu 4.10 (Warty Warthog)
http://security.ubuntu.com/ubuntu/pool/universe/a/apache/apache-doc_1. 3.31-6ubuntu0.4_all.deb -
Ubuntu apache-perl_1.3.31-6ubuntu0.4_amd64.deb
Ubuntu 4.10 (Warty Warthog)
http://security.ubuntu.com/ubuntu/pool/universe/a/apache/apache-perl_1 .3.31-6ubuntu0.4_amd64.deb -
Ubuntu apache-perl_1.3.31-6ubuntu0.4_i386.deb
Ubuntu 4.10 (Warty Warthog)
http://security.ubuntu.com/ubuntu/pool/universe/a/apache/apache-perl_1 .3.31-6ubuntu0.4_i386.deb -
Ubuntu apache-perl_1.3.31-6ubuntu0.4_powerpc.deb
Ubuntu 4.10 (Warty Warthog)
http://security.ubuntu.com/ubuntu/pool/universe/a/apache/apache-perl_1 .3.31-6ubuntu0.4_powerpc.deb -
Ubuntu apache-ssl_1.3.31-6ubuntu0.4_amd64.deb
Ubuntu 4.10 (Warty Warthog)
http://security.ubuntu.com/ubuntu/pool/universe/a/apache/apache-ssl_1. 3.31-6ubuntu0.4_amd64.deb -
Ubuntu apache-ssl_1.3.31-6ubuntu0.4_i386.deb
Ubuntu 4.10 (Warty Warthog)
http://security.ubuntu.com/ubuntu/pool/universe/a/apache/apache-ssl_1. 3.31-6ubuntu0.4_i386.deb -
Ubuntu apache-ssl_1.3.31-6ubuntu0.4_powerpc.deb
Ubuntu 4.10 (Warty Warthog)
http://security.ubuntu.com/ubuntu/pool/universe/a/apache/apache-ssl_1. 3.31-6ubuntu0.4_powerpc.deb -
Ubuntu apache-utils_1.3.31-6ubuntu0.4_amd64.deb
Ubuntu 4.10 (Warty Warthog)
http://security.ubuntu.com/ubuntu/pool/main/a/apache/apache-utils_1.3. 31-6ubuntu0.4_amd64.deb -
Ubuntu apache-utils_1.3.31-6ubuntu0.4_i386.deb
Ubuntu 4.10 (Warty Warthog)
http://security.ubuntu.com/ubuntu/pool/main/a/apache/apache-utils_1.3. 31-6ubuntu0.4_i386.deb -
Ubuntu apache-utils_1.3.31-6ubuntu0.4_powerpc.deb
Ubuntu 4.10 (Warty Warthog)
http://security.ubuntu.com/ubuntu/pool/main/a/apache/apache-utils_1.3. 31-6ubuntu0.4_powerpc.deb -
Ubuntu apache_1.3.31-6ubuntu0.4_amd64.deb
Ubuntu 4.10 (Warty Warthog)
http://security.ubuntu.com/ubuntu/pool/universe/a/apache/apache_1.3.31 -6ubuntu0.4_amd64.deb -
Ubuntu apache_1.3.31-6ubuntu0.4_i386.deb
Ubuntu 4.10 (Warty Warthog)
http://security.ubuntu.com/ubuntu/pool/universe/a/apache/apache_1.3.31 -6ubuntu0.4_i386.deb -
Ubuntu apache_1.3.31-6ubuntu0.4_powerpc.deb
Ubuntu 4.10 (Warty Warthog)
http://security.ubuntu.com/ubuntu/pool/universe/a/apache/apache_1.3.31 -6ubuntu0.4_powerpc.deb -
Ubuntu libapache-mod-perl_1.29.0.2-14ubuntu0.1_amd64.deb
Ubuntu 4.10 (Warty Warthog)
http://security.ubuntu.com/ubuntu/pool/universe/a/apache/libapache-mod -perl_1.29.0.2-14ubuntu0.1_amd64.deb -
Ubuntu libapache-mod-perl_1.29.0.2-14ubuntu0.1_i386.deb
Ubuntu 4.10 (Warty Warthog)
http://security.ubuntu.com/ubuntu/pool/universe/a/apache/libapache-mod -perl_1.29.0.2-14ubuntu0.1_i386.deb -
Ubuntu libapache-mod-perl_1.29.0.2-14ubuntu0.1_powerpc.deb
Ubuntu 4.10 (Warty Warthog)
http://security.ubuntu.com/ubuntu/pool/universe/a/apache/libapache-mod -perl_1.29.0.2-14ubuntu0.1_powerpc.deb
References
Apache Utilities Insecure Temporary File Creation Vulnerability
References:
References:
- Apache Homepage (Apache Software Foundation)
- Debian Bug report logs - #290974 - apache: Temporary usage bugs that can be used (Debian)