StoreBackup Insecure Temporary File Creation Vulnerability
BID:14985
Info
StoreBackup Insecure Temporary File Creation Vulnerability
| Bugtraq ID: | 14985 |
| Class: | Access Validation Error |
| CVE: | |
| Remote: | No |
| Local: | Yes |
| Published: | Sep 16 2005 12:00AM |
| Updated: | Dec 15 2006 09:03PM |
| Credit: | This vulnerability was announced by the vendor. |
| Vulnerable: |
storeBackup storeBackup 1.18.4 storeBackup storeBackup 1.18.3 storeBackup storeBackup 1.18.2 storeBackup storeBackup 1.18.1 storeBackup storeBackup 1.18 Debian Linux 3.1 sparc Debian Linux 3.1 s/390 Debian Linux 3.1 ppc Debian Linux 3.1 mipsel Debian Linux 3.1 mips Debian Linux 3.1 m68k Debian Linux 3.1 ia-64 Debian Linux 3.1 ia-32 Debian Linux 3.1 hppa Debian Linux 3.1 arm Debian Linux 3.1 amd64 Debian Linux 3.1 alpha Debian Linux 3.1 ARC ARC 5.21 j |
| Not Vulnerable: |
storeBackup storeBackup 1.19 |
Discussion
StoreBackup Insecure Temporary File Creation Vulnerability
storeBackup creates temporary files in an insecure manner.
An attacker with local access could potentially exploit this issue to view files and obtain privileged information. The attacker may also perform symlink attacks, overwriting arbitrary files in the context of the affected application.
Exploitation would most likely result in loss of confidentiality and theft of privileged information. Successful exploitation of a symlink attack may allow an attacker to overwrite sensitive configuration files. This may result in a denial of service; other attacks may also be possible.
storeBackup creates temporary files in an insecure manner.
An attacker with local access could potentially exploit this issue to view files and obtain privileged information. The attacker may also perform symlink attacks, overwriting arbitrary files in the context of the affected application.
Exploitation would most likely result in loss of confidentiality and theft of privileged information. Successful exploitation of a symlink attack may allow an attacker to overwrite sensitive configuration files. This may result in a denial of service; other attacks may also be possible.
Exploit / POC
StoreBackup Insecure Temporary File Creation Vulnerability
There is no exploit required.
There is no exploit required.
Solution / Fix
StoreBackup Insecure Temporary File Creation Vulnerability
Solution:
Please see the references for further information and vendor advisories.
The vendor has addressed this issue in storeBackup version 1.19.
storeBackup storeBackup 1.18
storeBackup storeBackup 1.18.1
storeBackup storeBackup 1.18.2
storeBackup storeBackup 1.18.3
storeBackup storeBackup 1.18.4
Solution:
Please see the references for further information and vendor advisories.
The vendor has addressed this issue in storeBackup version 1.19.
storeBackup storeBackup 1.18
-
storeBackup storeBackup-1.19.tar.bz2
http://prdownloads.sourceforge.net/storebackup/storeBackup-1.19.tar.bz 2?download
storeBackup storeBackup 1.18.1
-
storeBackup storeBackup-1.19.tar.bz2
http://prdownloads.sourceforge.net/storebackup/storeBackup-1.19.tar.bz 2?download
storeBackup storeBackup 1.18.2
-
storeBackup storeBackup-1.19.tar.bz2
http://prdownloads.sourceforge.net/storebackup/storeBackup-1.19.tar.bz 2?download
storeBackup storeBackup 1.18.3
-
storeBackup storeBackup-1.19.tar.bz2
http://prdownloads.sourceforge.net/storebackup/storeBackup-1.19.tar.bz 2?download
storeBackup storeBackup 1.18.4
-
Debian storebackup_1.18.4-2sarge1_all.deb
Debian GNU/Linux 3.1 alias sarge
http://security.debian.org/pool/updates/main/s/storebackup/storebackup _1.18.4-2sarge1_all.deb -
storeBackup storeBackup-1.19.tar.bz2
http://prdownloads.sourceforge.net/storebackup/storeBackup-1.19.tar.bz 2?download
References
StoreBackup Insecure Temporary File Creation Vulnerability
References:
References:
- ARC Web Site (ARC)
- storeBackup 1.19 Changelog (storeBackup)
- storeBackup Homepage (storeBackup)
- arc insecure temporary file creation (ZATAZ Audits
)