SILC Server Insecure Temporary File Creation Vulnerability
BID:14716
Info
SILC Server Insecure Temporary File Creation Vulnerability
| Bugtraq ID: | 14716 |
| Class: | Design Error |
| CVE: | |
| Remote: | No |
| Local: | Yes |
| Published: | Sep 01 2005 12:00AM |
| Updated: | Sep 01 2005 12:00AM |
| Credit: | This issue was disclosed by "Eric Romang / ZATAZ.com" <[email protected]>. |
| Vulnerable: |
SILC Secure Internet Live Conferencing 1.0 SILC Secure Internet Live Conferencing 0.9.21 SILC Secure Internet Live Conferencing 0.9.20 SILC Secure Internet Live Conferencing 0.9.19 SILC Secure Internet Live Conferencing 0.9.18 SILC Secure Internet Live Conferencing 0.9.17 SILC Secure Internet Live Conferencing 0.9.16 SILC Secure Internet Live Conferencing 0.9.15 SILC Secure Internet Live Conferencing 0.9.14 SILC Secure Internet Live Conferencing 0.9.13 SILC Secure Internet Live Conferencing 0.9.12 SILC Secure Internet Live Conferencing 0.9.11 Gentoo Linux |
| Not Vulnerable: | |
Discussion
SILC Server Insecure Temporary File Creation Vulnerability
SILC Server creates temporary files in an insecure manner. The issue exists in the 'silcd/silcd.c' file.
Exploitation would most likely result in loss of data or a denial of service if critical files are overwritten in the attack. Other attacks may be possible as well.
SILC Server creates temporary files in an insecure manner. The issue exists in the 'silcd/silcd.c' file.
Exploitation would most likely result in loss of data or a denial of service if critical files are overwritten in the attack. Other attacks may be possible as well.
Exploit / POC
SILC Server Insecure Temporary File Creation Vulnerability
There is no exploit required.
There is no exploit required.
Solution / Fix
SILC Server Insecure Temporary File Creation Vulnerability
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
References
SILC Server Insecure Temporary File Creation Vulnerability
References:
References:
- Bugzilla Bug 94587 - net-im/silc-server-0.9.21 insecure temporary file creation (Gentoo)
- SILC Webpage (SILC)
- silc server and toolkit insecure temporary file creation ("Eric Romang / ZATAZ.com"
)