HylaFAX Insecure Temporary File Creation Vulnerability
BID:14907
Info
HylaFAX Insecure Temporary File Creation Vulnerability
| Bugtraq ID: | 14907 |
| Class: | Design Error |
| CVE: |
CVE-2005-3069 |
| Remote: | No |
| Local: | Yes |
| Published: | Sep 22 2005 12:00AM |
| Updated: | Jul 12 2009 05:06PM |
| Credit: | Javier Fernandez-Sanguino Pena is credited with the discovery of this vulnerability. |
| Vulnerable: |
Mandriva Linux Mandrake 2006.0 x86_64 Mandriva Linux Mandrake 2006.0 Mandriva Linux Mandrake 10.2 x86_64 Mandriva Linux Mandrake 10.2 Mandriva Linux Mandrake 10.1 x86_64 Mandriva Linux Mandrake 10.1 MandrakeSoft Corporate Server 3.0 x86_64 MandrakeSoft Corporate Server 3.0 MandrakeSoft Corporate Server 2.1 x86_64 MandrakeSoft Corporate Server 2.1 Hylafax Hylafax 4.2.1 Debian Linux 3.1 sparc Debian Linux 3.1 s/390 Debian Linux 3.1 ppc Debian Linux 3.1 mipsel Debian Linux 3.1 mips Debian Linux 3.1 m68k Debian Linux 3.1 ia-64 Debian Linux 3.1 ia-32 Debian Linux 3.1 hppa Debian Linux 3.1 arm Debian Linux 3.1 amd64 Debian Linux 3.1 alpha Debian Linux 3.1 Debian Linux 3.0 sparc Debian Linux 3.0 s/390 Debian Linux 3.0 ppc Debian Linux 3.0 mipsel Debian Linux 3.0 mips Debian Linux 3.0 m68k Debian Linux 3.0 ia-64 Debian Linux 3.0 ia-32 Debian Linux 3.0 hppa Debian Linux 3.0 arm Debian Linux 3.0 alpha Debian Linux 3.0 |
| Not Vulnerable: | |
Discussion
HylaFAX Insecure Temporary File Creation Vulnerability
HylaFAX creates temporary files in an insecure manner. This may allow a local attacker to perform symbolic link attacks.
Successful exploitation may result in sensitive data or configuration files being overwritten. This may result in a denial of service; other attacks may also be possible.
HylaFAX creates temporary files in an insecure manner. This may allow a local attacker to perform symbolic link attacks.
Successful exploitation may result in sensitive data or configuration files being overwritten. This may result in a denial of service; other attacks may also be possible.
Exploit / POC
HylaFAX Insecure Temporary File Creation Vulnerability
No exploit is required.
No exploit is required.
Solution / Fix
HylaFAX Insecure Temporary File Creation Vulnerability
Solution:
Gentoo has released advisory GLSA 200509-21 to address this issue. Gentoo updates may be applied by running the following commands as the superuser:
emerge --sync
emerge --ask --oneshot --verbose net-misc/hylafax
Mandriva has released advisory MDKSA-2005:177, along with fixes to address this issue in various Mandrake Linux operating systems. Please see the referenced advisory for further information.
Debian Linux has released security advisory DSA 865-1 addressing this issue. Please see the referenced advisory for details on obtaining and applying the appropriate updates.
---
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Hylafax Hylafax 4.2.1
Solution:
Gentoo has released advisory GLSA 200509-21 to address this issue. Gentoo updates may be applied by running the following commands as the superuser:
emerge --sync
emerge --ask --oneshot --verbose net-misc/hylafax
Mandriva has released advisory MDKSA-2005:177, along with fixes to address this issue in various Mandrake Linux operating systems. Please see the referenced advisory for further information.
Debian Linux has released security advisory DSA 865-1 addressing this issue. Please see the referenced advisory for details on obtaining and applying the appropriate updates.
---
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Hylafax Hylafax 4.2.1
-
Debian hylafax-client_4.2.1-5sarge1_hppa.deb
Debian GNU/Linux 3.1 alias sarge
http://security.debian.org/pool/updates/main/h/hylafax/hylafax-client_ 4.2.1-5sarge1_hppa.deb -
Debian hylafax-client_4.2.1-5sarge1_i386.deb
Debian GNU/Linux 3.1 alias sarge
http://security.debian.org/pool/updates/main/h/hylafax/hylafax-client_ 4.2.1-5sarge1_i386.deb -
Debian hylafax-client_4.2.1-5sarge1_ia64.deb
Debian GNU/Linux 3.1 alias sarge
http://security.debian.org/pool/updates/main/h/hylafax/hylafax-client_ 4.2.1-5sarge1_ia64.deb -
Debian hylafax-client_4.2.1-5sarge1_m68k.deb
Debian GNU/Linux 3.1 alias sarge
http://security.debian.org/pool/updates/main/h/hylafax/hylafax-client_ 4.2.1-5sarge1_m68k.deb -
Debian hylafax-client_4.2.1-5sarge1_mips.deb
Debian GNU/Linux 3.1 alias sarge
http://security.debian.org/pool/updates/main/h/hylafax/hylafax-client_ 4.2.1-5sarge1_mips.deb -
Debian hylafax-client_4.2.1-5sarge1_mipsel.deb
Debian GNU/Linux 3.1 alias sarge
http://security.debian.org/pool/updates/main/h/hylafax/hylafax-client_ 4.2.1-5sarge1_mipsel.deb -
Debian hylafax-client_4.2.1-5sarge1_powerpc.deb
Debian GNU/Linux 3.1 alias sarge
http://security.debian.org/pool/updates/main/h/hylafax/hylafax-client_ 4.2.1-5sarge1_powerpc.deb -
Debian hylafax-client_4.2.1-5sarge1_s390.deb
Debian GNU/Linux 3.1 alias sarge
http://security.debian.org/pool/updates/main/h/hylafax/hylafax-client_ 4.2.1-5sarge1_s390.deb -
Debian hylafax-client_4.2.1-5sarge1_sparc.deb
Debian GNU/Linux 3.1 alias sarge
http://security.debian.org/pool/updates/main/h/hylafax/hylafax-client_ 4.2.1-5sarge1_sparc.deb -
Debian hylafax-server_4.2.1-5sarge1_arm.deb
Debian GNU/Linux 3.1 alias sarge
http://security.debian.org/pool/updates/main/h/hylafax/hylafax-server_ 4.2.1-5sarge1_arm.deb -
Debian hylafax-server_4.2.1-5sarge1_hppa.deb
Debian GNU/Linux 3.1 alias sarge
http://security.debian.org/pool/updates/main/h/hylafax/hylafax-server_ 4.2.1-5sarge1_hppa.deb -
Debian hylafax-server_4.2.1-5sarge1_i386.deb
Debian GNU/Linux 3.1 alias sarge
http://security.debian.org/pool/updates/main/h/hylafax/hylafax-server_ 4.2.1-5sarge1_i386.deb -
Debian hylafax-server_4.2.1-5sarge1_ia64.deb
Debian GNU/Linux 3.1 alias sarge
http://security.debian.org/pool/updates/main/h/hylafax/hylafax-server_ 4.2.1-5sarge1_ia64.deb -
Debian hylafax-server_4.2.1-5sarge1_m68k.deb
Debian GNU/Linux 3.1 alias sarge
http://security.debian.org/pool/updates/main/h/hylafax/hylafax-server_ 4.2.1-5sarge1_m68k.deb -
Debian hylafax-server_4.2.1-5sarge1_mips.deb
Debian GNU/Linux 3.1 alias sarge
http://security.debian.org/pool/updates/main/h/hylafax/hylafax-server_ 4.2.1-5sarge1_mips.deb -
Debian hylafax-server_4.2.1-5sarge1_mipsel.deb
Debian GNU/Linux 3.1 alias sarge
http://security.debian.org/pool/updates/main/h/hylafax/hylafax-server_ 4.2.1-5sarge1_mipsel.deb -
Debian hylafax-server_4.2.1-5sarge1_powerpc.deb
Debian GNU/Linux 3.1 alias sarge
http://security.debian.org/pool/updates/main/h/hylafax/hylafax-server_ 4.2.1-5sarge1_powerpc.deb -
Debian hylafax-server_4.2.1-5sarge1_s390.deb
Debian GNU/Linux 3.1 alias sarge
http://security.debian.org/pool/updates/main/h/hylafax/hylafax-server_ 4.2.1-5sarge1_s390.deb -
Debian hylafax-server_4.2.1-5sarge1_sparc.deb
Debian GNU/Linux 3.1 alias sarge
http://security.debian.org/pool/updates/main/h/hylafax/hylafax-server_ 4.2.1-5sarge1_sparc.deb -
Mandriva hylafax-4.2.1-2.1.20060mdk.i586.rpm
Mandrivalinux 2006.0:
http://www1.mandrivalinux.com/en/ftp.php3 -
Mandriva hylafax-4.2.1-2.1.20060mdk.x86_64.rpm
Mandrivalinux 2006.0/X86_64:
http://www1.mandrivalinux.com/en/ftp.php3 -
Mandriva hylafax-client-4.2.1-2.1.20060mdk.i586.rpm
Mandrivalinux 2006.0:
http://www1.mandrivalinux.com/en/ftp.php3 -
Mandriva hylafax-client-4.2.1-2.1.20060mdk.x86_64.rpm
Mandrivalinux 2006.0/X86_64:
http://www1.mandrivalinux.com/en/ftp.php3 -
Mandriva hylafax-server-4.2.1-2.1.20060mdk.i586.rpm
Mandrivalinux 2006.0:
http://www1.mandrivalinux.com/en/ftp.php3 -
Mandriva hylafax-server-4.2.1-2.1.20060mdk.x86_64.rpm
Mandrivalinux 2006.0/X86_64:
http://www1.mandrivalinux.com/en/ftp.php3 -
Mandriva lib64hylafax4.2.0-4.2.1-2.1.20060mdk.x86_64.rpm
Mandrivalinux 2006.0/X86_64:
http://www1.mandrivalinux.com/en/ftp.php3 -
Mandriva lib64hylafax4.2.0-devel-4.2.1-2.1.20060mdk.x86_64.rpm
Mandrivalinux 2006.0/X86_64:
http://www1.mandrivalinux.com/en/ftp.php3 -
Mandriva libhylafax4.2.0-4.2.1-2.1.20060mdk.i586.rpm
Mandrivalinux 2006.0:
http://www1.mandrivalinux.com/en/ftp.php3 -
Mandriva libhylafax4.2.0-devel-4.2.1-2.1.20060mdk.i586.rpm
Mandrivalinux 2006.0:
http://www1.mandrivalinux.com/en/ftp.php3
References
HylaFAX Insecure Temporary File Creation Vulnerability
References:
References:
- Hylafax Web Site (Hylafax)
- Temporary file vulnerability in xferfaxstats and other security concerns (Javier Fernández-Sanguino Peña )