XPVM Insecure Temporary File Creation Vulnerability
BID:14228
Info
XPVM Insecure Temporary File Creation Vulnerability
| Bugtraq ID: | 14228 |
| Class: | Design Error |
| CVE: |
CVE-2005-2240 |
| Remote: | No |
| Local: | Yes |
| Published: | Jul 12 2005 12:00AM |
| Updated: | Dec 15 2006 08:38PM |
| Credit: | Discovery is credited to zataz. |
| Vulnerable: |
XPVM XPVM 1.2.5 -r2 XPVM XPVM 1.2.5 XPVM XPVM 1.2.4 Debian Linux 3.1 sparc Debian Linux 3.1 s/390 Debian Linux 3.1 ppc Debian Linux 3.1 mipsel Debian Linux 3.1 mips Debian Linux 3.1 m68k Debian Linux 3.1 ia-64 Debian Linux 3.1 ia-32 Debian Linux 3.1 hppa Debian Linux 3.1 arm Debian Linux 3.1 amd64 Debian Linux 3.1 alpha Debian Linux 3.1 Debian Linux 3.0 sparc Debian Linux 3.0 s/390 Debian Linux 3.0 ppc Debian Linux 3.0 mipsel Debian Linux 3.0 mips Debian Linux 3.0 m68k Debian Linux 3.0 ia-64 Debian Linux 3.0 ia-32 Debian Linux 3.0 hppa Debian Linux 3.0 arm Debian Linux 3.0 alpha Debian Linux 3.0 |
| Not Vulnerable: | |
Discussion
XPVM Insecure Temporary File Creation Vulnerability
XPVM creates temporary files in an insecure manner.
A local attacker would most likely take advantage of this vulnerability by creating a malicious symbolic link in a directory where the temporary files will be created. When the program tries to perform an operation on a temporary file, it will instead perform the operation on the file pointed to by the malicious symlink.
Exploitation would most likely result in loss of data or a denial of service if critical files are overwritten in the attack. Other attacks may be possible as well.
XPVM creates temporary files in an insecure manner.
A local attacker would most likely take advantage of this vulnerability by creating a malicious symbolic link in a directory where the temporary files will be created. When the program tries to perform an operation on a temporary file, it will instead perform the operation on the file pointed to by the malicious symlink.
Exploitation would most likely result in loss of data or a denial of service if critical files are overwritten in the attack. Other attacks may be possible as well.
Exploit / POC
XPVM Insecure Temporary File Creation Vulnerability
No exploit is required.
No exploit is required.
Solution / Fix
XPVM Insecure Temporary File Creation Vulnerability
Solution:
Please see the references for more information and vendor advisories.
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected]:[email protected]
XPVM XPVM 1.2.5
Solution:
Please see the references for more information and vendor advisories.
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected]:[email protected]
XPVM XPVM 1.2.5
-
Debian xpvm_1.2.5-7.2woody1_alpha.deb
Debian GNU/Linux 3.0 alias woody
http://security.debian.org/pool/updates/main/x/xpvm/xpvm_1.2.5-7.2wood y1_alpha.deb -
Debian xpvm_1.2.5-7.2woody1_arm.deb
Debian GNU/Linux 3.0 alias woody
http://security.debian.org/pool/updates/main/x/xpvm/xpvm_1.2.5-7.2wood y1_arm.deb -
Debian xpvm_1.2.5-7.2woody1_hppa.deb
Debian GNU/Linux 3.0 alias woody
http://security.debian.org/pool/updates/main/x/xpvm/xpvm_1.2.5-7.2wood y1_hppa.deb -
Debian xpvm_1.2.5-7.2woody1_i386.deb
Debian GNU/Linux 3.0 alias woody
http://security.debian.org/pool/updates/main/x/xpvm/xpvm_1.2.5-7.2wood y1_i386.deb -
Debian xpvm_1.2.5-7.2woody1_ia64.deb
Debian GNU/Linux 3.0 alias woody
http://security.debian.org/pool/updates/main/x/xpvm/xpvm_1.2.5-7.2wood y1_ia64.deb -
Debian xpvm_1.2.5-7.2woody1_m68k.deb
Debian GNU/Linux 3.0 alias woody
http://security.debian.org/pool/updates/main/x/xpvm/xpvm_1.2.5-7.2wood y1_m68k.deb -
Debian xpvm_1.2.5-7.2woody1_mips.deb
Debian GNU/Linux 3.0 alias woody
http://security.debian.org/pool/updates/main/x/xpvm/xpvm_1.2.5-7.2wood y1_mips.deb -
Debian xpvm_1.2.5-7.2woody1_mipsel.deb
Debian GNU/Linux 3.0 alias woody
http://security.debian.org/pool/updates/main/x/xpvm/xpvm_1.2.5-7.2wood y1_mipsel.deb -
Debian xpvm_1.2.5-7.2woody1_powerpc.deb
Debian GNU/Linux 3.0 alias woody
http://security.debian.org/pool/updates/main/x/xpvm/xpvm_1.2.5-7.2wood y1_powerpc.deb -
Debian xpvm_1.2.5-7.2woody1_s390.deb
Debian GNU/Linux 3.0 alias woody
http://security.debian.org/pool/updates/main/x/xpvm/xpvm_1.2.5-7.2wood y1_s390.deb -
Debian xpvm_1.2.5-7.2woody1_sparc.deb
Debian GNU/Linux 3.0 alias woody
http://security.debian.org/pool/updates/main/x/xpvm/xpvm_1.2.5-7.2wood y1_sparc.deb -
Debian xpvm_1.2.5-7.3sarge1_alpha.deb
Debian GNU/Linux 3.1 alias sarge
http://security.debian.org/pool/updates/main/x/xpvm/xpvm_1.2.5-7.3sarg e1_alpha.deb -
Debian xpvm_1.2.5-7.3sarge1_amd64.deb
Debian GNU/Linux 3.1 alias sarge
http://security.debian.org/pool/updates/main/x/xpvm/xpvm_1.2.5-7.3sarg e1_amd64.deb -
Debian xpvm_1.2.5-7.3sarge1_arm.deb
Debian GNU/Linux 3.1 alias sarge
http://security.debian.org/pool/updates/main/x/xpvm/xpvm_1.2.5-7.3sarg e1_arm.deb -
Debian xpvm_1.2.5-7.3sarge1_hppa.deb
Debian GNU/Linux 3.1 alias sarge
http://security.debian.org/pool/updates/main/x/xpvm/xpvm_1.2.5-7.3sarg e1_hppa.deb -
Debian xpvm_1.2.5-7.3sarge1_i386.deb
Debian GNU/Linux 3.1 alias sarge
http://security.debian.org/pool/updates/main/x/xpvm/xpvm_1.2.5-7.3sarg e1_i386.deb -
Debian xpvm_1.2.5-7.3sarge1_ia64.deb
Debian GNU/Linux 3.1 alias sarge
http://security.debian.org/pool/updates/main/x/xpvm/xpvm_1.2.5-7.3sarg e1_ia64.deb -
Debian xpvm_1.2.5-7.3sarge1_m68k.deb
Debian GNU/Linux 3.1 alias sarge
http://security.debian.org/pool/updates/main/x/xpvm/xpvm_1.2.5-7.3sarg e1_m68k.deb -
Debian xpvm_1.2.5-7.3sarge1_mips.deb
Debian GNU/Linux 3.1 alias sarge
http://security.debian.org/pool/updates/main/x/xpvm/xpvm_1.2.5-7.3sarg e1_mips.deb -
Debian xpvm_1.2.5-7.3sarge1_mipsel.deb
Debian GNU/Linux 3.1 alias sarge
http://security.debian.org/pool/updates/main/x/xpvm/xpvm_1.2.5-7.3sarg e1_mipsel.deb -
Debian xpvm_1.2.5-7.3sarge1_powerpc.deb
Debian GNU/Linux 3.1 alias sarge
http://security.debian.org/pool/updates/main/x/xpvm/xpvm_1.2.5-7.3sarg e1_powerpc.deb -
Debian xpvm_1.2.5-7.3sarge1_s390.deb
Debian GNU/Linux 3.1 alias sarge
http://security.debian.org/pool/updates/main/x/xpvm/xpvm_1.2.5-7.3sarg e1_s390.deb -
Debian xpvm_1.2.5-7.3sarge1_sparc.deb
Debian GNU/Linux 3.1 alias sarge
http://security.debian.org/pool/updates/main/x/xpvm/xpvm_1.2.5-7.3sarg e1_sparc.deb