EKG Insecure Temporary File Creation Vulnerability
BID:14146
Info
EKG Insecure Temporary File Creation Vulnerability
| Bugtraq ID: | 14146 |
| Class: | Design Error |
| CVE: |
CVE-2005-1916 |
| Remote: | No |
| Local: | Yes |
| Published: | Jul 05 2005 12:00AM |
| Updated: | Jul 12 2009 04:06PM |
| Credit: | Discovery is credited to Eric Romang of zataz. |
| Vulnerable: |
Ubuntu Ubuntu Linux 5.0 4 powerpc Ubuntu Ubuntu Linux 5.0 4 i386 Ubuntu Ubuntu Linux 5.0 4 amd64 Log4sh Log4sh 1.2.5 Log4sh Log4sh 1.2.4 Log4sh Log4sh 1.2.3 ekg ekg 2005-06-05 22:03 ekg ekg 2005-04-11 Debian Linux 3.1 sparc Debian Linux 3.1 s/390 Debian Linux 3.1 ppc Debian Linux 3.1 mipsel Debian Linux 3.1 mips Debian Linux 3.1 m68k Debian Linux 3.1 ia-64 Debian Linux 3.1 ia-32 Debian Linux 3.1 hppa Debian Linux 3.1 arm Debian Linux 3.1 alpha Debian Linux 3.1 |
| Not Vulnerable: |
Log4sh Log4sh 1.2.6 ekg ekg 1.6 rc3 ekg ekg 1.6 rc2 |
Discussion
EKG Insecure Temporary File Creation Vulnerability
ekg creates temporary files in an insecure manner. An attacker will local access could potentially exploit this issue to overwrite files in the context of the application.
Exploitation would most likely result in loss of data or a denial of service if critical files are overwritten in the attack. There is also an unconfirmed potential for privilege escalation if the attacker can write custom data in the attack.
ekg creates temporary files in an insecure manner. An attacker will local access could potentially exploit this issue to overwrite files in the context of the application.
Exploitation would most likely result in loss of data or a denial of service if critical files are overwritten in the attack. There is also an unconfirmed potential for privilege escalation if the attacker can write custom data in the attack.
Exploit / POC
EKG Insecure Temporary File Creation Vulnerability
There is no exploit required.
There is no exploit required.
Solution / Fix
EKG Insecure Temporary File Creation Vulnerability
Solution:
Debian has released advisory DSA 760-1 to address this issue. Please see the referenced advisory for more information.
Ubuntu Linux has released advisory USN-162-1, along with fixes to address various issues. Please see the referenced advisory for further information.
Debian has released security advisory DSA 773-1 addressing several issues for their AMD64 port of the operating system. Please see the referenced advisory for further information.
The vendor has addressed this and other issues in ekg version 1.6rc2 and later:
ekg ekg 2005-04-11
ekg ekg 2005-06-05 22:03
Log4sh Log4sh 1.2.3
Log4sh Log4sh 1.2.4
Log4sh Log4sh 1.2.5
Solution:
Debian has released advisory DSA 760-1 to address this issue. Please see the referenced advisory for more information.
Ubuntu Linux has released advisory USN-162-1, along with fixes to address various issues. Please see the referenced advisory for further information.
Debian has released security advisory DSA 773-1 addressing several issues for their AMD64 port of the operating system. Please see the referenced advisory for further information.
The vendor has addressed this and other issues in ekg version 1.6rc2 and later:
ekg ekg 2005-04-11
-
ekg ekg-1.6rc3.tar.gz
http://dev.null.pl/ekg/ekg-1.6rc3.tar.gz
ekg ekg 2005-06-05 22:03
-
ekg ekg-1.6rc3.tar.gz
http://dev.null.pl/ekg/ekg-1.6rc3.tar.gz
Log4sh Log4sh 1.2.3
-
Log4sh log4sh-1.2.6.tgz
http://prdownloads.sourceforge.net/log4sh/log4sh-1.2.6.tgz?use_mirror= umn
Log4sh Log4sh 1.2.4
-
Log4sh log4sh-1.2.6.tgz
http://prdownloads.sourceforge.net/log4sh/log4sh-1.2.6.tgz?use_mirror= umn
Log4sh Log4sh 1.2.5
-
Log4sh log4sh-1.2.6.tgz
http://prdownloads.sourceforge.net/log4sh/log4sh-1.2.6.tgz?use_mirror= umn
References
EKG Insecure Temporary File Creation Vulnerability
References:
References:
- ekg Homepage (ekg)
- ekg insecure temporary file creation and arbitrary code execution (zataz)
- Log4sh Homepage (Log4sh)
- log4sh insecure temporary file creation (zataz)
- ekg insecure temporary file creation and arbitrary code execution (ZATAZ Audits
) - Multiple vulnerabilities in libgadu and ekg package (Wojtek Kaniewski
)