ApacheTop Insecure Temporary File Creation Vulnerability
BID:14982
Info
ApacheTop Insecure Temporary File Creation Vulnerability
| Bugtraq ID: | 14982 |
| Class: | Design Error |
| CVE: |
CVE-2005-2660 |
| Remote: | No |
| Local: | Yes |
| Published: | Sep 30 2005 12:00AM |
| Updated: | Jul 12 2009 05:06PM |
| Credit: | Eric Romang ([email protected] - ZATAZ Audit) is credited with the discovery of this vulnerability. |
| Vulnerable: |
ApacheTop ApacheTop 0.12.5 |
| Not Vulnerable: | |
Discussion
ApacheTop Insecure Temporary File Creation Vulnerability
ApacheTop creates temporary files in an insecure manner. This may allow a local attacker to perform symbolic link attacks.
Successful exploitation may result in sensitive data or configuration files being overwritten. This may result in a denial of service; other attacks may also be possible.
ApacheTop creates temporary files in an insecure manner. This may allow a local attacker to perform symbolic link attacks.
Successful exploitation may result in sensitive data or configuration files being overwritten. This may result in a denial of service; other attacks may also be possible.
Exploit / POC
ApacheTop Insecure Temporary File Creation Vulnerability
No exploit is required.
No exploit is required.
Solution / Fix
ApacheTop Insecure Temporary File Creation Vulnerability
Solution:
Debian Linux has released security advisory DSA 839-1 addressing this issue. Please see the referenced advisory for more information.
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
ApacheTop ApacheTop 0.12.5
Solution:
Debian Linux has released security advisory DSA 839-1 addressing this issue. Please see the referenced advisory for more information.
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
ApacheTop ApacheTop 0.12.5
-
Debian apachetop_0.12.5-1sarge1_alpha.deb
Debian GNU/Linux 3.1 alias sarge
http://security.debian.org/pool/updates/main/a/apachetop/apachetop_0.1 2.5-1sarge1_alpha.deb -
Debian apachetop_0.12.5-1sarge1_amd64.deb
Debian GNU/Linux 3.1 alias sarge
http://security.debian.org/pool/updates/main/a/apachetop/apachetop_0.1 2.5-1sarge1_amd64.deb -
Debian apachetop_0.12.5-1sarge1_arm.deb
Debian GNU/Linux 3.1 alias sarge
http://security.debian.org/pool/updates/main/a/apachetop/apachetop_0.1 2.5-1sarge1_arm.deb -
Debian apachetop_0.12.5-1sarge1_hppa.deb
Debian GNU/Linux 3.1 alias sarge
http://security.debian.org/pool/updates/main/a/apachetop/apachetop_0.1 2.5-1sarge1_hppa.deb -
Debian apachetop_0.12.5-1sarge1_i386.deb
Debian GNU/Linux 3.1 alias sarge
http://security.debian.org/pool/updates/main/a/apachetop/apachetop_0.1 2.5-1sarge1_i386.deb -
Debian apachetop_0.12.5-1sarge1_ia64.deb
Debian GNU/Linux 3.1 alias sarge
http://security.debian.org/pool/updates/main/a/apachetop/apachetop_0.1 2.5-1sarge1_ia64.deb -
Debian apachetop_0.12.5-1sarge1_m68k.deb
Debian GNU/Linux 3.1 alias sarge
http://security.debian.org/pool/updates/main/a/apachetop/apachetop_0.1 2.5-1sarge1_m68k.deb -
Debian apachetop_0.12.5-1sarge1_mips.deb
Debian GNU/Linux 3.1 alias sarge
http://security.debian.org/pool/updates/main/a/apachetop/apachetop_0.1 2.5-1sarge1_mips.deb -
Debian apachetop_0.12.5-1sarge1_mipsel.deb
Debian GNU/Linux 3.1 alias sarge
http://security.debian.org/pool/updates/main/a/apachetop/apachetop_0.1 2.5-1sarge1_mipsel.deb -
Debian apachetop_0.12.5-1sarge1_powerpc.deb
Debian GNU/Linux 3.1 alias sarge
http://security.debian.org/pool/updates/main/a/apachetop/apachetop_0.1 2.5-1sarge1_powerpc.deb -
Debian apachetop_0.12.5-1sarge1_s390.deb
Debian GNU/Linux 3.1 alias sarge
http://security.debian.org/pool/updates/main/a/apachetop/apachetop_0.1 2.5-1sarge1_s390.deb -
Debian apachetop_0.12.5-1sarge1_sparc.deb
Debian GNU/Linux 3.1 alias sarge
http://security.debian.org/pool/updates/main/a/apachetop/apachetop_0.1 2.5-1sarge1_sparc.deb
References
ApacheTop Insecure Temporary File Creation Vulnerability
References:
References:
- ApacheTop Homepage (ApacheTop)
- Bugzilla Bug 104473 - app-admin/apachetop <= 0.12.5 insecure tmp file creation (Gentoo)
- apachetop insecure temporary file creation (ZATAZ Audits
)