Debian Module-Assistant Insecure Temporary File Creation Vulnerability
BID:15151
Info
Debian Module-Assistant Insecure Temporary File Creation Vulnerability
| Bugtraq ID: | 15151 |
| Class: | Design Error |
| CVE: |
CVE-2005-3121 |
| Remote: | No |
| Local: | Yes |
| Published: | Oct 20 2005 12:00AM |
| Updated: | Jul 12 2009 05:56PM |
| Credit: | Eduard Bloch discovered this vulnerability. |
| Vulnerable: |
Debian module-assistant |
| Not Vulnerable: |
Debian module-assistant 0.9.10 Debian module-assistant 0.9 sarge1 |
Discussion
Debian Module-Assistant Insecure Temporary File Creation Vulnerability
Debian module-assistant creates temporary files in an insecure manner.
Exploitation would most likely result in loss of data or a denial of service if critical files are overwritten in the attack. Other attacks may be possible as well.
Debian module-assistant creates temporary files in an insecure manner.
Exploitation would most likely result in loss of data or a denial of service if critical files are overwritten in the attack. Other attacks may be possible as well.
Exploit / POC
Debian Module-Assistant Insecure Temporary File Creation Vulnerability
An exploit is not required.
An exploit is not required.
Solution / Fix
Debian Module-Assistant Insecure Temporary File Creation Vulnerability
Solution:
Debian GNU/Linux has released advisory DSA 867-1, along with fixes to address this issue. Please see the referenced advisory for further information.
Users are encouraged to utilize the 'apt-get' utility to obtain fixes.
Solution:
Debian GNU/Linux has released advisory DSA 867-1, along with fixes to address this issue. Please see the referenced advisory for further information.
Users are encouraged to utilize the 'apt-get' utility to obtain fixes.
References
Debian Module-Assistant Insecure Temporary File Creation Vulnerability
References:
References: