Pine RPDump Local File Corruption Vulnerability
BID:13093
Info
Pine RPDump Local File Corruption Vulnerability
| Bugtraq ID: | 13093 |
| Class: | Race Condition Error |
| CVE: |
CVE-2005-1066 |
| Remote: | No |
| Local: | Yes |
| Published: | Apr 11 2005 12:00AM |
| Updated: | Jul 12 2009 12:56PM |
| Credit: | Imran Ghory <[email protected]> is credited with the discovery of this vulnerability. |
| Vulnerable: |
University of Washington Pine 4.62 University of Washington Pine 4.58 University of Washington Pine 4.56 University of Washington Pine 4.53 University of Washington Pine 4.52 University of Washington Pine 4.50 University of Washington Pine 4.44 University of Washington Pine 4.33 University of Washington Pine 4.30 University of Washington Pine 4.21 University of Washington Pine 4.20 University of Washington Pine 4.10 University of Washington Pine 4.2 x University of Washington Pine 4.0.4 University of Washington Pine 4.0.2 |
| Not Vulnerable: | |
Discussion
Pine RPDump Local File Corruption Vulnerability
Pine 'rpdump' is reported prone to a race condition vulnerability. The issue exists because a window of opportunity exists between the time that the software checks if a user supplied local file exists, and the time that the file is opened for writing.
If 'rpdump' is being invoked against an existing file that resides in a local world-writable directory, an attacker may potentially replace the file with a hardlink to a target file. The attacker may accomplish this while the vulnerable software is processing the remote file. If successful, data that was supposed for the existing file will instead be written to the linked file.
Pine version 4.62 is reported vulnerable, other versions might also be affected.
Pine 'rpdump' is reported prone to a race condition vulnerability. The issue exists because a window of opportunity exists between the time that the software checks if a user supplied local file exists, and the time that the file is opened for writing.
If 'rpdump' is being invoked against an existing file that resides in a local world-writable directory, an attacker may potentially replace the file with a hardlink to a target file. The attacker may accomplish this while the vulnerable software is processing the remote file. If successful, data that was supposed for the existing file will instead be written to the linked file.
Pine version 4.62 is reported vulnerable, other versions might also be affected.
Exploit / POC
Pine RPDump Local File Corruption Vulnerability
No exploit is required.
No exploit is required.
Solution / Fix
Pine RPDump Local File Corruption Vulnerability
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
References
Pine RPDump Local File Corruption Vulnerability
References:
References:
- Pine Homepage/Information (University of Washington)
- rpdump TOCTOU file-permissions vulnerability (Imran Ghory
)