ELMO Insecure Temporary File Creation Vulnerability
BID:14235
Info
ELMO Insecure Temporary File Creation Vulnerability
| Bugtraq ID: | 14235 |
| Class: | Design Error |
| CVE: | |
| Remote: | No |
| Local: | Yes |
| Published: | Jul 12 2005 12:00AM |
| Updated: | Jul 12 2005 12:00AM |
| Credit: | Discovery is credited to Eric Romang. |
| Vulnerable: |
ELMO ELMO 1.3.2 -r1 |
| Not Vulnerable: | |
Discussion
ELMO Insecure Temporary File Creation Vulnerability
ELMO creates temporary files in an insecure manner.
A local attacker would most likely take advantage of this vulnerability by creating a malicious symbolic link in a directory where the temporary files will be created. When the program attempts to perform an operation on a temporary file, it will instead perform the operation on the file pointed to by the malicious symbolic link.
Exploitation would most likely result in loss of data or a denial of service if critical files are overwritten in the attack. Other attacks may be possible as well.
ELMO creates temporary files in an insecure manner.
A local attacker would most likely take advantage of this vulnerability by creating a malicious symbolic link in a directory where the temporary files will be created. When the program attempts to perform an operation on a temporary file, it will instead perform the operation on the file pointed to by the malicious symbolic link.
Exploitation would most likely result in loss of data or a denial of service if critical files are overwritten in the attack. Other attacks may be possible as well.
Exploit / POC
ELMO Insecure Temporary File Creation Vulnerability
There is no exploit required.
There is no exploit required.
Solution / Fix
ELMO Insecure Temporary File Creation Vulnerability
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.