Crip Helper Script Insecure Temporary File Creation Vulnerability
BID:14105
Info
Crip Helper Script Insecure Temporary File Creation Vulnerability
| Bugtraq ID: | 14105 |
| Class: | Design Error |
| CVE: |
CVE-2005-0393 |
| Remote: | No |
| Local: | Yes |
| Published: | Jun 30 2005 12:00AM |
| Updated: | Jul 12 2009 04:06PM |
| Credit: | Discovery is credited to Justin Rye. |
| Vulnerable: |
Debian Linux 3.1 sparc Debian Linux 3.1 s/390 Debian Linux 3.1 ppc Debian Linux 3.1 mipsel Debian Linux 3.1 mips Debian Linux 3.1 m68k Debian Linux 3.1 ia-64 Debian Linux 3.1 ia-32 Debian Linux 3.1 hppa Debian Linux 3.1 arm Debian Linux 3.1 amd64 Debian Linux 3.1 alpha Debian Linux 3.1 Charlton crip 3.5 |
| Not Vulnerable: | |
Discussion
Crip Helper Script Insecure Temporary File Creation Vulnerability
The crip helper scripts create temporary files in an insecure manner. An attacker will local access could potentially exploit this issue to overwrite files in the context of the application.
Exploitation would most likely result in loss of data or a denial of service if critical files are overwritten in the attack. There is also an unconfirmed potential for privilege escalation if the attacker can write custom data in the attack.
This issue is known to affect crip 3.5. Other releases may also be affected.
The crip helper scripts create temporary files in an insecure manner. An attacker will local access could potentially exploit this issue to overwrite files in the context of the application.
Exploitation would most likely result in loss of data or a denial of service if critical files are overwritten in the attack. There is also an unconfirmed potential for privilege escalation if the attacker can write custom data in the attack.
This issue is known to affect crip 3.5. Other releases may also be affected.
Exploit / POC
Crip Helper Script Insecure Temporary File Creation Vulnerability
There is no exploit required.
There is no exploit required.
Solution / Fix
Crip Helper Script Insecure Temporary File Creation Vulnerability
Solution:
Debian has released an advisory to address this vulnerability. For further information on obtaining and applying fixes, please see the attached Debian advisory.
It is not known if the vendor has fixed this vulnerability in upstream releases.
Debian has released security advisory DSA 773-1 addressing several issues for their AMD64 port of the operating system. Please see the referenced advisory for further information.
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Charlton crip 3.5
Solution:
Debian has released an advisory to address this vulnerability. For further information on obtaining and applying fixes, please see the attached Debian advisory.
It is not known if the vendor has fixed this vulnerability in upstream releases.
Debian has released security advisory DSA 773-1 addressing several issues for their AMD64 port of the operating system. Please see the referenced advisory for further information.
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Charlton crip 3.5
-
Debian crip_3.5-1sarge2_alpha.deb
Debian GNU/Linux 3.1 alias sarge
http://security.debian.org/pool/updates/main/c/crip/crip_3.5-1sarge2_a lpha.deb -
Debian crip_3.5-1sarge2_amd64.deb
Debian GNU/Linux 3.1 alias sarge
http://security.debian.org/pool/updates/main/c/crip/crip_3.5-1sarge2_a md64.deb -
Debian crip_3.5-1sarge2_arm.deb
Debian GNU/Linux 3.1 alias sarge
http://security.debian.org/pool/updates/main/c/crip/crip_3.5-1sarge2_a rm.deb -
Debian crip_3.5-1sarge2_hppa.deb
Debian GNU/Linux 3.1 alias sarge
http://security.debian.org/pool/updates/main/c/crip/crip_3.5-1sarge2_h ppa.deb -
Debian crip_3.5-1sarge2_i386.deb
Debian GNU/Linux 3.1 alias sarge
http://security.debian.org/pool/updates/main/c/crip/crip_3.5-1sarge2_i 386.deb -
Debian crip_3.5-1sarge2_ia64.deb
Debian GNU/Linux 3.1 alias sarge
http://security.debian.org/pool/updates/main/c/crip/crip_3.5-1sarge2_i a64.deb -
Debian crip_3.5-1sarge2_m68k.deb
Debian GNU/Linux 3.1 alias sarge
http://security.debian.org/pool/updates/main/c/crip/crip_3.5-1sarge2_m 68k.deb -
Debian crip_3.5-1sarge2_mips.deb
Debian GNU/Linux 3.1 alias sarge
http://security.debian.org/pool/updates/main/c/crip/crip_3.5-1sarge2_m ips.deb -
Debian crip_3.5-1sarge2_mipsel.deb
Debian GNU/Linux 3.1 alias sarge
http://security.debian.org/pool/updates/main/c/crip/crip_3.5-1sarge2_m ipsel.deb -
Debian crip_3.5-1sarge2_powerpc.deb
Debian GNU/Linux 3.1 alias sarge
http://security.debian.org/pool/updates/main/c/crip/crip_3.5-1sarge2_p owerpc.deb -
Debian crip_3.5-1sarge2_s390.deb
Debian GNU/Linux 3.1 alias sarge
http://security.debian.org/pool/updates/main/c/crip/crip_3.5-1sarge2_s 390.deb -
Debian crip_3.5-1sarge2_sparc.deb
Debian GNU/Linux 3.1 alias sarge
http://security.debian.org/pool/updates/main/c/crip/crip_3.5-1sarge2_s parc.deb
References
Crip Helper Script Insecure Temporary File Creation Vulnerability
References:
References:
- crip Homepage (Charlton)