Gentoo Sandbox Multiple Insecure Temporary File Creation Vulnerabilities
BID:14375
Info
Gentoo Sandbox Multiple Insecure Temporary File Creation Vulnerabilities
| Bugtraq ID: | 14375 |
| Class: | Design Error |
| CVE: | |
| Remote: | No |
| Local: | Yes |
| Published: | Jul 25 2005 12:00AM |
| Updated: | Jul 25 2005 12:00AM |
| Credit: | Discovery is credited to Tavis Ormandy of the Gentoo Linux Security Audit Team. |
| Vulnerable: |
Gentoo Linux |
| Not Vulnerable: | |
Discussion
Gentoo Sandbox Multiple Insecure Temporary File Creation Vulnerabilities
Sandbox is reported prone to multiple local insecure temporary file creation vulnerabilities. These issues are due to design errors that cause the application to fail to verify the existence of files before writing to them.
This application runs with superuser privileges, allowing local attackers to overwrite arbitrary files. This may cause system-wide crashes, denying service to legitimate users. It may also be possible to gain elevated privileges by exploiting this vulnerability, but this has not been confirmed.
Sandbox is reported prone to multiple local insecure temporary file creation vulnerabilities. These issues are due to design errors that cause the application to fail to verify the existence of files before writing to them.
This application runs with superuser privileges, allowing local attackers to overwrite arbitrary files. This may cause system-wide crashes, denying service to legitimate users. It may also be possible to gain elevated privileges by exploiting this vulnerability, but this has not been confirmed.
Exploit / POC
Gentoo Sandbox Multiple Insecure Temporary File Creation Vulnerabilities
An exploit is not required.
An exploit is not required.
Solution / Fix
Gentoo Sandbox Multiple Insecure Temporary File Creation Vulnerabilities
Solution:
Gentoo has released an advisory (GLSA 200507-22) to address this issue. Gentoo users may apply the updates by issuing the following sequence of commands as a superuser:
emerge --sync
emerge --ask --oneshot --verbose ">=sys-apps/sandbox-1.2.11"
Solution:
Gentoo has released an advisory (GLSA 200507-22) to address this issue. Gentoo users may apply the updates by issuing the following sequence of commands as a superuser:
emerge --sync
emerge --ask --oneshot --verbose ">=sys-apps/sandbox-1.2.11"
References
Gentoo Sandbox Multiple Insecure Temporary File Creation Vulnerabilities
References:
References: