F2C Multiple Local Insecure Temporary File Creation Vulnerabilities
BID:12380
Info
F2C Multiple Local Insecure Temporary File Creation Vulnerabilities
| Bugtraq ID: | 12380 |
| Class: | Design Error |
| CVE: |
CVE-2005-0017 CVE-2005-0018 |
| Remote: | No |
| Local: | Yes |
| Published: | Jan 27 2005 12:00AM |
| Updated: | Jul 12 2009 10:06AM |
| Credit: | Javier Fernández-Sanguino Peña is credited with the discovery of this issue. |
| Vulnerable: |
f2c Fortran 77 Translator 1.3.1 |
| Not Vulnerable: | |
Discussion
F2C Multiple Local Insecure Temporary File Creation Vulnerabilities
Multiple local insecure temporary file creation vulnerabilities affect f2c. These issues are due to a design error causing failure of the application to write to temporary files securely.
An attacker may leverage these issues to corrupt arbitrary files with the privileges of an unsuspecting user that executes the affected applications.
Multiple local insecure temporary file creation vulnerabilities affect f2c. These issues are due to a design error causing failure of the application to write to temporary files securely.
An attacker may leverage these issues to corrupt arbitrary files with the privileges of an unsuspecting user that executes the affected applications.
Exploit / POC
F2C Multiple Local Insecure Temporary File Creation Vulnerabilities
No exploit is required to leverage this issue.
No exploit is required to leverage this issue.
Solution / Fix
F2C Multiple Local Insecure Temporary File Creation Vulnerabilities
Solution:
Debian Linux has released advisory DSA 661-1 along with fixes dealing with this issue. Please see the referenced advisory for more information.
Gentoo has released advisory GLSA 200501-43 to address these issues. Gentoo users may carry out the following commands to update their computers:
emerge --sync
emerge --ask --oneshot --verbose ">=dev-lang/f2c-20030320-r1"
Please see the referenced Gentoo advisory for more information.
Debian has released a new advisory DSA 661-2 to address problems with the original fixes. The fixes did not properly correct the issue. Please see the referenced advisory for links to new fixes.
f2c Fortran 77 Translator 1.3.1
Solution:
Debian Linux has released advisory DSA 661-1 along with fixes dealing with this issue. Please see the referenced advisory for more information.
Gentoo has released advisory GLSA 200501-43 to address these issues. Gentoo users may carry out the following commands to update their computers:
emerge --sync
emerge --ask --oneshot --verbose ">=dev-lang/f2c-20030320-r1"
Please see the referenced Gentoo advisory for more information.
Debian has released a new advisory DSA 661-2 to address problems with the original fixes. The fixes did not properly correct the issue. Please see the referenced advisory for links to new fixes.
f2c Fortran 77 Translator 1.3.1
-
Debian f2c_20010821-3.1_alpha.deb
Debian GNU/Linux 3.0 alias woody
http://security.debian.org/pool/updates/main/f/f2c/f2c_20010821-3.1_al pha.deb -
Debian f2c_20010821-3.1_arm.deb
Debian GNU/Linux 3.0 alias woody
http://security.debian.org/pool/updates/main/f/f2c/f2c_20010821-3.1_ar m.deb -
Debian f2c_20010821-3.1_hppa.deb
Debian GNU/Linux 3.0 alias woody
http://security.debian.org/pool/updates/main/f/f2c/f2c_20010821-3.1_hp pa.deb -
Debian f2c_20010821-3.1_i386.deb
Debian GNU/Linux 3.0 alias woody
http://security.debian.org/pool/updates/main/f/f2c/f2c_20010821-3.1_i3 86.deb -
Debian f2c_20010821-3.1_ia64.deb
Debian GNU/Linux 3.0 alias woody
http://security.debian.org/pool/updates/main/f/f2c/f2c_20010821-3.1_ia 64.deb -
Debian f2c_20010821-3.1_m68k.deb
Debian GNU/Linux 3.0 alias woody
http://security.debian.org/pool/updates/main/f/f2c/f2c_20010821-3.1_m6 8k.deb -
Debian f2c_20010821-3.1_mips.deb
Debian GNU/Linux 3.0 alias woody
http://security.debian.org/pool/updates/main/f/f2c/f2c_20010821-3.1_mi ps.deb -
Debian f2c_20010821-3.1_mipsel.deb
Debian GNU/Linux 3.0 alias woody
http://security.debian.org/pool/updates/main/f/f2c/f2c_20010821-3.1_mi psel.deb -
Debian f2c_20010821-3.1_powerpc.deb
Debian GNU/Linux 3.0 alias woody
http://security.debian.org/pool/updates/main/f/f2c/f2c_20010821-3.1_po werpc.deb -
Debian f2c_20010821-3.1_s390.deb
Debian GNU/Linux 3.0 alias woody
http://security.debian.org/pool/updates/main/f/f2c/f2c_20010821-3.1_s3 90.deb -
Debian f2c_20010821-3.1_sparc.deb
Debian GNU/Linux 3.0 alias woody
http://security.debian.org/pool/updates/main/f/f2c/f2c_20010821-3.1_sp arc.deb -
Debian f2c_20010821-3.2_alpha.deb
Debian GNU/Linux 3.0 alias woody
http://security.debian.org/pool/updates/main/f/f2c/f2c_20010821-3.2_al pha.deb -
Debian f2c_20010821-3.2_arm.deb
Debian GNU/Linux 3.0 alias woody
http://security.debian.org/pool/updates/main/f/f2c/f2c_20010821-3.2_ar m.deb -
Debian f2c_20010821-3.2_hppa.deb
Debian GNU/Linux 3.0 alias woody
http://security.debian.org/pool/updates/main/f/f2c/f2c_20010821-3.2_hp pa.deb -
Debian f2c_20010821-3.2_i386.deb
Debian GNU/Linux 3.0 alias woody
http://security.debian.org/pool/updates/main/f/f2c/f2c_20010821-3.2_i3 86.deb -
Debian f2c_20010821-3.2_ia64.deb
Debian GNU/Linux 3.0 alias woody
http://security.debian.org/pool/updates/main/f/f2c/f2c_20010821-3.2_ia 64.deb -
Debian f2c_20010821-3.2_m68k.deb
Debian GNU/Linux 3.0 alias woody
http://security.debian.org/pool/updates/main/f/f2c/f2c_20010821-3.2_m6 8k.deb -
Debian f2c_20010821-3.2_mips.deb
Debian GNU/Linux 3.0 alias woody
http://security.debian.org/pool/updates/main/f/f2c/f2c_20010821-3.2_mi ps.deb -
Debian f2c_20010821-3.2_mipsel.deb
Debian GNU/Linux 3.0 alias woody
http://security.debian.org/pool/updates/main/f/f2c/f2c_20010821-3.2_mi psel.deb -
Debian f2c_20010821-3.2_powerpc.deb
Debian GNU/Linux 3.0 alias woody
http://security.debian.org/pool/updates/main/f/f2c/f2c_20010821-3.2_po werpc.deb -
Debian f2c_20010821-3.2_s390.deb
Debian GNU/Linux 3.0 alias woody
http://security.debian.org/pool/updates/main/f/f2c/f2c_20010821-3.2_s3 90.deb -
Debian f2c_20010821-3.2_sparc.deb
Debian GNU/Linux 3.0 alias woody
http://security.debian.org/pool/updates/main/f/f2c/f2c_20010821-3.2_sp arc.deb