Popper Insecure Temporary File Creation Vulnerability
BID:14149
Info
Popper Insecure Temporary File Creation Vulnerability
| Bugtraq ID: | 14149 |
| Class: | Design Error |
| CVE: |
CVE-2005-1917 |
| Remote: | No |
| Local: | Yes |
| Published: | Jul 05 2005 12:00AM |
| Updated: | Jul 12 2009 04:06PM |
| Credit: | Discovery is credited to zataz. |
| Vulnerable: |
Popper Popper 1.0 Popper Popper 0.93 Log4sh Log4sh 1.2.5 Log4sh Log4sh 1.2.4 Log4sh Log4sh 1.2.3 |
| Not Vulnerable: |
Log4sh Log4sh 1.2.6 |
Discussion
Popper Insecure Temporary File Creation Vulnerability
Popper creates temporary files in an insecure manner. An attacker with local access could potentially exploit this issue to overwrite files in the context of the application.
Exploitation would most likely result in loss of data or a denial of service if critical files are overwritten in the attack. There is also an unconfirmed potential for privilege escalation if the attacker can write custom data in the attack.
Popper creates temporary files in an insecure manner. An attacker with local access could potentially exploit this issue to overwrite files in the context of the application.
Exploitation would most likely result in loss of data or a denial of service if critical files are overwritten in the attack. There is also an unconfirmed potential for privilege escalation if the attacker can write custom data in the attack.
Exploit / POC
Popper Insecure Temporary File Creation Vulnerability
There is no exploit required.
There is no exploit required.
Solution / Fix
Popper Insecure Temporary File Creation Vulnerability
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Log4sh Log4sh 1.2.3
Log4sh Log4sh 1.2.4
Log4sh Log4sh 1.2.5
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Log4sh Log4sh 1.2.3
-
Log4sh log4sh-1.2.6.tgz
http://prdownloads.sourceforge.net/log4sh/log4sh-1.2.6.tgz?use_mirror= umn
Log4sh Log4sh 1.2.4
-
Log4sh log4sh-1.2.6.tgz
http://prdownloads.sourceforge.net/log4sh/log4sh-1.2.6.tgz?use_mirror= umn
Log4sh Log4sh 1.2.5
-
Log4sh log4sh-1.2.6.tgz
http://prdownloads.sourceforge.net/log4sh/log4sh-1.2.6.tgz?use_mirror= umn
References
Popper Insecure Temporary File Creation Vulnerability
References:
References:
- kpopper insecure temporary file creation (zataz)
- Log4sh Homepage (Log4sh)
- log4sh insecure temporary file creation (zataz)
- Popper Homepage (Popper)