EveryBuddy Autotrans.C Insecure Temporary File Creation Vulnerability
BID:13865
Info
EveryBuddy Autotrans.C Insecure Temporary File Creation Vulnerability
| Bugtraq ID: | 13865 |
| Class: | Access Validation Error |
| CVE: |
CVE-2005-1880 |
| Remote: | No |
| Local: | Yes |
| Published: | Jun 06 2005 12:00AM |
| Updated: | Jul 12 2009 02:56PM |
| Credit: | Discovery is credited to Eric Romang <[email protected]>. |
| Vulnerable: |
MySQL AB MySQL 5.0.4 MySQL AB MySQL 5.0.3 MySQL AB MySQL 5.0.2 MySQL AB MySQL 5.0.1 MySQL AB MySQL 5.0 .0-alpha MySQL AB MySQL 5.0 .0-0 MySQL AB MySQL 4.0.11 -gamma MySQL AB MySQL 4.0.11 MySQL AB MySQL 4.0.10 MySQL AB MySQL 4.0.9 -gamma MySQL AB MySQL 4.0.9 MySQL AB MySQL 4.0.8 -gamma MySQL AB MySQL 4.0.8 MySQL AB MySQL 4.0.7 -gamma MySQL AB MySQL 4.0.7 MySQL AB MySQL 4.0.6 MySQL AB MySQL 4.0.5 a MySQL AB MySQL 4.0.5 MySQL AB MySQL 4.0.4 MySQL AB MySQL 4.0.3 MySQL AB MySQL 4.0.2 MySQL AB MySQL 4.0.1 MySQL AB MySQL 4.0 .0 EveryBuddy EveryBuddy 0.4.3 |
| Not Vulnerable: |
MySQL AB MySQL 4.0.12 |
Discussion
EveryBuddy Autotrans.C Insecure Temporary File Creation Vulnerability
EveryBuddy is reportedly affected by an insecure temporary file creation vulnerability.
The vulnerability arises when EveryBuddy executes and creates a temporary file in the '/tmp' folder with a predictable filename.
EveryBuddy releases up to version 0.4.3 are reported vulnerable.
EveryBuddy is reportedly affected by an insecure temporary file creation vulnerability.
The vulnerability arises when EveryBuddy executes and creates a temporary file in the '/tmp' folder with a predictable filename.
EveryBuddy releases up to version 0.4.3 are reported vulnerable.
Exploit / POC
EveryBuddy Autotrans.C Insecure Temporary File Creation Vulnerability
An exploit is not required.
An exploit is not required.
Solution / Fix
EveryBuddy Autotrans.C Insecure Temporary File Creation Vulnerability
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
References
EveryBuddy Autotrans.C Insecure Temporary File Creation Vulnerability
References:
References:
- MySQL Homepage (Oracle)
- everybuddy <= 0.4.3 insecure temporary file creation (Eric Romang / DATACENTER Luxembourg
)