Gentoo Webapp-Config Insecure File Creation Vulnerability
BID:13780
Info
Gentoo Webapp-Config Insecure File Creation Vulnerability
| Bugtraq ID: | 13780 |
| Class: | Design Error |
| CVE: | |
| Remote: | No |
| Local: | Yes |
| Published: | May 26 2005 12:00AM |
| Updated: | May 26 2005 12:00AM |
| Credit: | Eric Romang ([email protected] - ZATAZ Audit) is credited with the discovery of this vulnerability. |
| Vulnerable: |
Gentoo webapp-config 1.10 r13 Gentoo webapp-config 1.10 r12 Gentoo webapp-config 1.10 r10 |
| Not Vulnerable: |
Gentoo webapp-config 1.11 Gentoo webapp-config 1.10 r14 |
Discussion
Gentoo Webapp-Config Insecure File Creation Vulnerability
Gentoo webapp-config is prone to an insecure file creation vulnerability. This issue is due to a design error that causes the application to fail to verify the existence of a file before writing to it.
An attacker may leverage this issue to cause arbitrary shell commands to be executed with superuser privileges.
Gentoo webapp-config is prone to an insecure file creation vulnerability. This issue is due to a design error that causes the application to fail to verify the existence of a file before writing to it.
An attacker may leverage this issue to cause arbitrary shell commands to be executed with superuser privileges.
Exploit / POC
Gentoo Webapp-Config Insecure File Creation Vulnerability
The following proof of concept exploit is available:
The following proof of concept exploit is available:
Solution / Fix
Gentoo Webapp-Config Insecure File Creation Vulnerability
Solution:
Gentoo has released advisory GLSA 200506-13 to address this issue. Users of affected packages are urged to execute the following commands with superuser privileges:
emerge --sync
emerge --ask --oneshot --verbose ">=net-www/webapp-config-1.11"
Please see the referenced advisory for further information.
Solution:
Gentoo has released advisory GLSA 200506-13 to address this issue. Users of affected packages are urged to execute the following commands with superuser privileges:
emerge --sync
emerge --ask --oneshot --verbose ">=net-www/webapp-config-1.11"
Please see the referenced advisory for further information.
References
Gentoo Webapp-Config Insecure File Creation Vulnerability
References:
References: