CVS Cvsbug.In Script Insecure Temporary File Creation Vulnerability
BID:14648
Info
CVS Cvsbug.In Script Insecure Temporary File Creation Vulnerability
| Bugtraq ID: | 14648 |
| Class: | Design Error |
| CVE: |
CVE-2005-2693 |
| Remote: | No |
| Local: | Yes |
| Published: | Aug 19 2005 12:00AM |
| Updated: | Jul 12 2009 05:06PM |
| Credit: | Discovery is credited to Josh Bressers. |
| Vulnerable: |
Trustix Secure Linux 3.0 Trustix Secure Linux 2.2 Trustix Secure Enterprise Linux 2.0 SGI ProPack 3.0 SP6 Redhat Enterprise Linux WS 4 Redhat Enterprise Linux WS 3 Redhat Enterprise Linux WS 2.1 IA64 Redhat Enterprise Linux WS 2.1 Redhat Enterprise Linux ES 4 Redhat Enterprise Linux ES 3 Redhat Enterprise Linux ES 2.1 IA64 Redhat Enterprise Linux ES 2.1 Redhat Enterprise Linux AS 4 Redhat Enterprise Linux AS 3 Redhat Enterprise Linux AS 2.1 IA64 Redhat Enterprise Linux AS 2.1 Redhat Desktop 4.0 Redhat Desktop 3.0 Redhat Advanced Workstation for the Itanium Processor 2.1 IA64 Redhat Advanced Workstation for the Itanium Processor 2.1 NetBSD NetBSD 2.0.2 NetBSD NetBSD 2.0.1 NetBSD NetBSD 2.0 NetBSD NetBSD 1.6.2 NetBSD NetBSD 1.6.1 NetBSD NetBSD 1.6 beta NetBSD NetBSD 1.6 NetBSD NetBSD 1.5.3 NetBSD NetBSD 1.5.2 NetBSD NetBSD 1.5.1 NetBSD NetBSD 1.5 x86 NetBSD NetBSD 1.5 sh3 NetBSD NetBSD 1.5 NetBSD NetBSD 1.4.3 NetBSD NetBSD 1.4.2 x86 NetBSD NetBSD 1.4.2 SPARC NetBSD NetBSD 1.4.2 arm32 NetBSD NetBSD 1.4.2 Alpha NetBSD NetBSD 1.4.2 NetBSD NetBSD 1.4.1 x86 NetBSD NetBSD 1.4.1 SPARC NetBSD NetBSD 1.4.1 sh3 NetBSD NetBSD 1.4.1 arm32 NetBSD NetBSD 1.4.1 Alpha NetBSD NetBSD 1.4.1 NetBSD NetBSD 1.4 x86 NetBSD NetBSD 1.4 SPARC NetBSD NetBSD 1.4 arm32 NetBSD NetBSD 1.4 Alpha NetBSD NetBSD 1.4 NetBSD NetBSD 1.3.3 NetBSD NetBSD 1.3.2 NetBSD NetBSD 1.3.1 NetBSD NetBSD 1.3 NetBSD NetBSD 1.2.1 NetBSD NetBSD 1.2 NetBSD NetBSD 1.1 NetBSD NetBSD 1.0 gcvs gcvs 1.0 final gcvs gcvs 1.0 a7 FreeBSD FreeBSD 5.4 -RELENG FreeBSD FreeBSD 5.4 -RELEASE FreeBSD FreeBSD 5.4 -PRERELEASE FreeBSD FreeBSD 5.3 -STABLE FreeBSD FreeBSD 5.3 -RELENG FreeBSD FreeBSD 5.3 -RELEASE FreeBSD FreeBSD 5.3 FreeBSD FreeBSD 5.2.1 -RELEASE FreeBSD FreeBSD 5.2 -RELENG FreeBSD FreeBSD 5.2 -RELEASE FreeBSD FreeBSD 5.2 FreeBSD FreeBSD 5.1 -RELENG FreeBSD FreeBSD 5.1 -RELEASE/Alpha FreeBSD FreeBSD 5.1 -RELEASE-p5 FreeBSD FreeBSD 5.1 -RELEASE FreeBSD FreeBSD 5.1 FreeBSD FreeBSD 5.0 -RELENG FreeBSD FreeBSD 5.0 -RELEASE-p14 FreeBSD FreeBSD 5.0 alpha FreeBSD FreeBSD 5.0 FreeBSD FreeBSD 4.11 -STABLE FreeBSD FreeBSD 4.11 -RELENG FreeBSD FreeBSD 4.11 -RELEASE-p3 FreeBSD FreeBSD 4.10 -RELENG FreeBSD FreeBSD 4.10 -RELEASE-p8 FreeBSD FreeBSD 4.10 -RELEASE FreeBSD FreeBSD 4.10 FreeBSD FreeBSD 4.9 -RELENG FreeBSD FreeBSD 4.9 -PRERELEASE FreeBSD FreeBSD 4.9 FreeBSD FreeBSD 4.8 -RELENG FreeBSD FreeBSD 4.8 -RELEASE-p7 FreeBSD FreeBSD 4.8 -PRERELEASE FreeBSD FreeBSD 4.8 FreeBSD FreeBSD 4.7 -STABLE FreeBSD FreeBSD 4.7 -RELENG FreeBSD FreeBSD 4.7 -RELEASE-p17 FreeBSD FreeBSD 4.7 -RELEASE FreeBSD FreeBSD 4.7 FreeBSD FreeBSD 4.6.2 FreeBSD FreeBSD 4.6 -STABLE FreeBSD FreeBSD 4.6 -RELENG FreeBSD FreeBSD 4.6 -RELEASE-p20 FreeBSD FreeBSD 4.6 -RELEASE FreeBSD FreeBSD 4.6 FreeBSD FreeBSD 4.5 -STABLEpre2002-03-07 FreeBSD FreeBSD 4.5 -STABLE FreeBSD FreeBSD 4.5 -RELENG FreeBSD FreeBSD 4.5 -RELEASE-p32 FreeBSD FreeBSD 4.5 -RELEASE FreeBSD FreeBSD 4.5 FreeBSD FreeBSD 4.4 -STABLE FreeBSD FreeBSD 4.4 -RELENG FreeBSD FreeBSD 4.4 -RELENG FreeBSD FreeBSD 4.4 -RELEASE-p42 FreeBSD FreeBSD 4.4 FreeBSD FreeBSD 4.3 -STABLE FreeBSD FreeBSD 4.3 -RELENG FreeBSD FreeBSD 4.3 -RELEASE-p38 FreeBSD FreeBSD 4.3 -RELEASE FreeBSD FreeBSD 4.3 FreeBSD FreeBSD 4.2 -STABLEpre122300 FreeBSD FreeBSD 4.2 -STABLEpre050201 FreeBSD FreeBSD 4.2 -STABLE FreeBSD FreeBSD 4.2 -RELEASE FreeBSD FreeBSD 4.2 FreeBSD FreeBSD 4.1.1 -STABLE FreeBSD FreeBSD 4.1.1 -RELEASE FreeBSD FreeBSD 4.1.1 FreeBSD FreeBSD 4.1 FreeBSD FreeBSD 4.0 .x FreeBSD FreeBSD 4.0 -RELENG FreeBSD FreeBSD 4.0 alpha FreeBSD FreeBSD 4.0 FreeBSD FreeBSD 3.5.1 -STABLEpre2001-07-20 FreeBSD FreeBSD 3.5.1 -STABLE FreeBSD FreeBSD 3.5.1 -RELEASE FreeBSD FreeBSD 3.5.1 FreeBSD FreeBSD 3.5 x FreeBSD FreeBSD 3.5 -STABLEpre122300 FreeBSD FreeBSD 3.5 -STABLEpre050201 FreeBSD FreeBSD 3.5 -STABLE FreeBSD FreeBSD 3.5 FreeBSD FreeBSD 3.4 x FreeBSD FreeBSD 3.4 FreeBSD FreeBSD 3.3 x FreeBSD FreeBSD 3.3 FreeBSD FreeBSD 3.2 x FreeBSD FreeBSD 3.2 FreeBSD FreeBSD 3.1 x FreeBSD FreeBSD 3.1 FreeBSD FreeBSD 3.0 -RELENG FreeBSD FreeBSD 3.0 FreeBSD FreeBSD 2.2.8 FreeBSD FreeBSD 2.2.6 FreeBSD FreeBSD 2.2.5 FreeBSD FreeBSD 2.2.4 FreeBSD FreeBSD 2.2.3 FreeBSD FreeBSD 2.2.2 FreeBSD FreeBSD 2.2 x FreeBSD FreeBSD 2.2 FreeBSD FreeBSD 2.1.7 .1 FreeBSD FreeBSD 2.1.6 .1 FreeBSD FreeBSD 2.1.6 FreeBSD FreeBSD 2.1.5 FreeBSD FreeBSD 2.1 x FreeBSD FreeBSD 2.1 FreeBSD FreeBSD 2.0.5 FreeBSD FreeBSD 2.0 FreeBSD FreeBSD 1.1.5 .1 FreeBSD FreeBSD 4.10-PRERELEASE FreeBSD FreeBSD 3.x FreeBSD FreeBSD 2.x FreeBSD FreeBSD -current Debian Linux 3.1 sparc Debian Linux 3.1 s/390 Debian Linux 3.1 ppc Debian Linux 3.1 mipsel Debian Linux 3.1 mips Debian Linux 3.1 m68k Debian Linux 3.1 ia-64 Debian Linux 3.1 ia-32 Debian Linux 3.1 hppa Debian Linux 3.1 arm Debian Linux 3.1 amd64 Debian Linux 3.1 alpha Debian Linux 3.1 CVS CVS 1.12.12 CVS CVS 1.12.11 CVS CVS 1.12.10 CVS CVS 1.12.9 CVS CVS 1.12.8 CVS CVS 1.12.7 CVS CVS 1.12.5 CVS CVS 1.12.2 CVS CVS 1.12.1 CVS CVS 1.11.19 CVS CVS 1.11.17 CVS CVS 1.11.1 |
| Not Vulnerable: |
NetBSD NetBSD 2.0.3 |
Discussion
CVS Cvsbug.In Script Insecure Temporary File Creation Vulnerability
CVS creates temporary files in an insecure manner.
The vulnerability is due to the program creating temporary files with a predictable name in the '/tmp' directory.
Exploitation would most likely result in loss of data or a denial of service if critical files are overwritten in the attack. Other attacks may be possible as well.
CVS creates temporary files in an insecure manner.
The vulnerability is due to the program creating temporary files with a predictable name in the '/tmp' directory.
Exploitation would most likely result in loss of data or a denial of service if critical files are overwritten in the attack. Other attacks may be possible as well.
Exploit / POC
CVS Cvsbug.In Script Insecure Temporary File Creation Vulnerability
There is no exploit required.
There is no exploit required.
Solution / Fix
CVS Cvsbug.In Script Insecure Temporary File Creation Vulnerability
Solution:
Fedora advisories FEDORA-2005-790 and FEDORA-2005-791 are available for Fedora Core 3 and Fedora Core 4 to address this issue. Please see the referenced advisories for more information.
Trustix Secure Linux has released security advisory TSLSA-2005-0045 addressing this and other issues. Please see the referenced advisory for details on obtaining and applying the appropriate updates.
Red Hat advisory RHSA-2005:756-3 is available to address this issue. Please see the referenced advisory for more information.
Debian has released advisory DSA 802-1 to address this issue. Please see the referenced advisory for more information.
FreeBSD has released security advisory FreeBSD-SA-05:20 addressing this issue. Please see the referenced advisory for further information.
SGI has released Security Update #46 to address this and other issues for SGI Propack 3 Service Pack 6. Please see the referenced advisory for further information.
Debian has released advisory DSA 806-1 to address this issue. Please see the referenced advisory for more information.
FreeBSD has released an updated version of their advisory FreeBSD-SA-05:20 containing additional patches. Please see the referenced advisory for further information.
NetBSD has released version 2.0.3 of the NetBSD operating system to address this, and other issues. Please see the referenced release announcement for further information.
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
CVS CVS 1.11.17
CVS CVS 1.11.19
SGI ProPack 3.0 SP6
FreeBSD FreeBSD 4.11 -RELEASE-p3
FreeBSD FreeBSD 5.3
FreeBSD FreeBSD 5.4 -RELENG
Solution:
Fedora advisories FEDORA-2005-790 and FEDORA-2005-791 are available for Fedora Core 3 and Fedora Core 4 to address this issue. Please see the referenced advisories for more information.
Trustix Secure Linux has released security advisory TSLSA-2005-0045 addressing this and other issues. Please see the referenced advisory for details on obtaining and applying the appropriate updates.
Red Hat advisory RHSA-2005:756-3 is available to address this issue. Please see the referenced advisory for more information.
Debian has released advisory DSA 802-1 to address this issue. Please see the referenced advisory for more information.
FreeBSD has released security advisory FreeBSD-SA-05:20 addressing this issue. Please see the referenced advisory for further information.
SGI has released Security Update #46 to address this and other issues for SGI Propack 3 Service Pack 6. Please see the referenced advisory for further information.
Debian has released advisory DSA 806-1 to address this issue. Please see the referenced advisory for more information.
FreeBSD has released an updated version of their advisory FreeBSD-SA-05:20 containing additional patches. Please see the referenced advisory for further information.
NetBSD has released version 2.0.3 of the NetBSD operating system to address this, and other issues. Please see the referenced release announcement for further information.
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
CVS CVS 1.11.17
-
RedHat Fedora cvs-1.11.17-7.FC3.i386.rpm
Fedora Core 3
http://download.fedora.redhat.com/pub/fedora/linux/core/updates/3/ -
RedHat Fedora cvs-1.11.17-7.FC3.x86_64.rpm
Fedora Core 3
http://download.fedora.redhat.com/pub/fedora/linux/core/updates/3/ -
RedHat Fedora cvs-debuginfo-1.11.17-7.FC3.i386.rpm
Fedora Core 3
http://download.fedora.redhat.com/pub/fedora/linux/core/updates/3/ -
RedHat Fedora cvs-debuginfo-1.11.17-7.FC3.x86_64.rpm
Fedora Core 3
http://download.fedora.redhat.com/pub/fedora/linux/core/updates/3/
CVS CVS 1.11.19
-
RedHat Fedora cvs-1.11.19-9.i386.rpm
Fedora Core 4
http://download.fedora.redhat.com/pub/fedora/linux/core/updates/4/ -
RedHat Fedora cvs-1.11.19-9.ppc.rpm
Fedora Core 4
http://download.fedora.redhat.com/pub/fedora/linux/core/updates/4/ -
RedHat Fedora cvs-1.11.19-9.x86_64.rpm
Fedora Core 4
http://download.fedora.redhat.com/pub/fedora/linux/core/updates/4/ -
RedHat Fedora cvs-debuginfo-1.11.19-9.i386.rpm
Fedora Core 4
http://download.fedora.redhat.com/pub/fedora/linux/core/updates/4/ -
RedHat Fedora cvs-debuginfo-1.11.19-9.ppc.rpm
Fedora Core 4
http://download.fedora.redhat.com/pub/fedora/linux/core/updates/4/ -
RedHat Fedora cvs-debuginfo-1.11.19-9.x86_64.rpm
Fedora Core 4
http://download.fedora.redhat.com/pub/fedora/linux/core/updates/4/
SGI ProPack 3.0 SP6
-
SGI Patch 10212
http://support.sgi.com/
FreeBSD FreeBSD 4.11 -RELEASE-p3
-
FreeBSD cvsbug.patch
ftp://ftp.FreeBSD.org/pub/FreeBSD/CERT/patches/SA-05:20/cvsbug.patch -
FreeBSD cvsbug.patch.asc
ftp://ftp.FreeBSD.org/pub/FreeBSD/CERT/patches/SA-05:20/cvsbug.patch.a sc
FreeBSD FreeBSD 5.3
-
FreeBSD cvsbug.patch
ftp://ftp.FreeBSD.org/pub/FreeBSD/CERT/patches/SA-05:20/cvsbug.patch -
FreeBSD cvsbug.patch.asc
ftp://ftp.FreeBSD.org/pub/FreeBSD/CERT/patches/SA-05:20/cvsbug.patch.a sc -
FreeBSD cvsbug53.patch
ftp://ftp.FreeBSD.org/pub/FreeBSD/CERT/patches/SA-05:20/cvsbug53.patch -
FreeBSD cvsbug53.patch.asc
ftp://ftp.FreeBSD.org/pub/FreeBSD/CERT/patches/SA-05:20/cvsbug53.patch .asc
FreeBSD FreeBSD 5.4 -RELENG
-
FreeBSD cvsbug.patch
ftp://ftp.FreeBSD.org/pub/FreeBSD/CERT/patches/SA-05:20/cvsbug.patch -
FreeBSD cvsbug.patch.asc
ftp://ftp.FreeBSD.org/pub/FreeBSD/CERT/patches/SA-05:20/cvsbug.patch.a sc
References
CVS Cvsbug.In Script Insecure Temporary File Creation Vulnerability
References:
References:
- Bugzilla Bug 166366 ? CVS temporary file issue (RedHat)
- CVS Home Page (CVS)
- RHSA-2005:756-3 - cvs security update (RedHat)