EKG Insecure Temporary File Creation Vulnerability
BID:14307
Info
EKG Insecure Temporary File Creation Vulnerability
| Bugtraq ID: | 14307 |
| Class: | Design Error |
| CVE: |
CVE-2005-1850 |
| Remote: | No |
| Local: | Yes |
| Published: | Jul 18 2005 12:00AM |
| Updated: | Jul 12 2009 04:06PM |
| Credit: | Discovery is credited to Marcin Owsiany and Wojtek Kaniewski. |
| Vulnerable: |
Ubuntu Ubuntu Linux 5.0 4 powerpc Ubuntu Ubuntu Linux 5.0 4 i386 Ubuntu Ubuntu Linux 5.0 4 amd64 ekg ekg 2005-04-11 |
| Not Vulnerable: |
ekg ekg 1.6 rc3 ekg ekg 1.6 rc2 |
Discussion
EKG Insecure Temporary File Creation Vulnerability
ekg is reported prone to an unspecified insecure temporary file creation vulnerability. This issue is likely due to a design error that causes the application to fail to verify the existence of a file before writing to it.
The details available regarding this issue are not sufficient to provide an in depth technical description. This BID will be updated when more information becomes available.
An attacker may leverage this issue to overwrite arbitrary files with the privileges of an unsuspecting user that activates the vulnerable application.
ekg is reported prone to an unspecified insecure temporary file creation vulnerability. This issue is likely due to a design error that causes the application to fail to verify the existence of a file before writing to it.
The details available regarding this issue are not sufficient to provide an in depth technical description. This BID will be updated when more information becomes available.
An attacker may leverage this issue to overwrite arbitrary files with the privileges of an unsuspecting user that activates the vulnerable application.
Exploit / POC
EKG Insecure Temporary File Creation Vulnerability
An exploit is not required.
An exploit is not required.
Solution / Fix
EKG Insecure Temporary File Creation Vulnerability
Solution:
Debian has released advisory DSA 760-1 to address this issue. Please see the referenced advisory for more information.
Ubuntu Linux has released advisory USN-162-1, along with fixes to address various issues. Please see the referenced advisory for further information.
Debian has released security advisory DSA 773-1 addressing several issues for their AMD64 port of the operating system. Please see the referenced advisory for further information.
The vendor has addressed this and other issues in ekg verion 1.6rc2 and later:
ekg ekg 2005-04-11
Solution:
Debian has released advisory DSA 760-1 to address this issue. Please see the referenced advisory for more information.
Ubuntu Linux has released advisory USN-162-1, along with fixes to address various issues. Please see the referenced advisory for further information.
Debian has released security advisory DSA 773-1 addressing several issues for their AMD64 port of the operating system. Please see the referenced advisory for further information.
The vendor has addressed this and other issues in ekg verion 1.6rc2 and later:
ekg ekg 2005-04-11
-
ekg ekg-1.6rc3.tar.gz
http://dev.null.pl/ekg/ekg-1.6rc3.tar.gz
References
EKG Insecure Temporary File Creation Vulnerability
References:
References:
- ekg Homepage (ekg)
- Multiple vulnerabilities in libgadu and ekg package (Wojtek Kaniewski
)