Gopher Insecure Temporary File Creation Vulnerability
BID:14420
Info
Gopher Insecure Temporary File Creation Vulnerability
| Bugtraq ID: | 14420 |
| Class: | Design Error |
| CVE: |
CVE-2005-1853 |
| Remote: | No |
| Local: | Yes |
| Published: | Jul 29 2005 12:00AM |
| Updated: | Jul 12 2009 04:06PM |
| Credit: | John Goerzen is credited with the discovery of this vulnerability. |
| Vulnerable: |
University of Minnesota gopherd 3.0.9 University of Minnesota gopherd 3.0.7 University of Minnesota gopherd 3.0.5 University of Minnesota gopherd 3.0.3 |
| Not Vulnerable: | |
Discussion
Gopher Insecure Temporary File Creation Vulnerability
Gopher is prone to an unspecified insecure temporary file creation vulnerability. This issue is likely due to a design error that causes the application to fail to verify the existence of a file before writing to it.
The details available regarding this issue are not sufficient to provide an in depth technical description. This BID will be updated when more information becomes available.
An attacker may leverage this issue to overwrite arbitrary files with the privileges of an unsuspecting user that activates the vulnerable application.
Gopher is prone to an unspecified insecure temporary file creation vulnerability. This issue is likely due to a design error that causes the application to fail to verify the existence of a file before writing to it.
The details available regarding this issue are not sufficient to provide an in depth technical description. This BID will be updated when more information becomes available.
An attacker may leverage this issue to overwrite arbitrary files with the privileges of an unsuspecting user that activates the vulnerable application.
Exploit / POC
Gopher Insecure Temporary File Creation Vulnerability
No exploit is required.
No exploit is required.
Solution / Fix
Gopher Insecure Temporary File Creation Vulnerability
Solution:
Debian has released security advisory DSA 770-1 addressing this issue. Please see the referenced advisory for details on obtaining and applying the appropriate updates.
Debian has released security advisory DSA 773-1 addressing several issues for their AMD64 port of the operating system. Please see the referenced
advisory for further information.
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
University of Minnesota gopherd 3.0.7
Solution:
Debian has released security advisory DSA 770-1 addressing this issue. Please see the referenced advisory for details on obtaining and applying the appropriate updates.
Debian has released security advisory DSA 773-1 addressing several issues for their AMD64 port of the operating system. Please see the referenced
advisory for further information.
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
University of Minnesota gopherd 3.0.7
-
Debian gopher_3.0.7sarge1_amd64.deb
Debian GNU/Linux 3.1 alias sarge
http://security.debian.org/pool/updates/main/g/gopher/gopher_3.0.7sarg e1_amd64.deb
References
Gopher Insecure Temporary File Creation Vulnerability
References:
References:
- Computer Science & Engineering (University Of Minnesota)