Wine WineLauncher.IN Local Insecure File Creation Vulnerability
BID:14496
Info
Wine WineLauncher.IN Local Insecure File Creation Vulnerability
| Bugtraq ID: | 14496 |
| Class: | Design Error |
| CVE: | |
| Remote: | No |
| Local: | Yes |
| Published: | Aug 08 2005 12:00AM |
| Updated: | Aug 08 2005 12:00AM |
| Credit: | Javier Fernandez-Sanguino Pena is credited with the discovery of this issue. |
| Vulnerable: |
Wine Windows API Emulator 20050725 |
| Not Vulnerable: | |
Discussion
Wine WineLauncher.IN Local Insecure File Creation Vulnerability
A local insecure file creation vulnerability affects Wine. This issue is likely due to a design error that causes the application to fail to verify the existence of a file before writing to it.
The details available regarding this issue are not sufficient to provide an in depth technical description. This BID will be updated when more information becomes available.
An attacker may leverage this issue to overwrite arbitrary files with the privileges of an unsuspecting user that activates the vulnerable application.
This issue is reported in version 20050725; other version may also be affected.
A local insecure file creation vulnerability affects Wine. This issue is likely due to a design error that causes the application to fail to verify the existence of a file before writing to it.
The details available regarding this issue are not sufficient to provide an in depth technical description. This BID will be updated when more information becomes available.
An attacker may leverage this issue to overwrite arbitrary files with the privileges of an unsuspecting user that activates the vulnerable application.
This issue is reported in version 20050725; other version may also be affected.
Exploit / POC
Wine WineLauncher.IN Local Insecure File Creation Vulnerability
No exploit is required to leverage this issue.
No exploit is required to leverage this issue.
Solution / Fix
Wine WineLauncher.IN Local Insecure File Creation Vulnerability
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.