NetBSD Insecure Temporary File Creation Vulnerability
BID:15263
Info
NetBSD Insecure Temporary File Creation Vulnerability
| Bugtraq ID: | 15263 |
| Class: | Design Error |
| CVE: | |
| Remote: | No |
| Local: | Yes |
| Published: | Nov 01 2005 12:00AM |
| Updated: | Nov 01 2005 12:00AM |
| Credit: | The vendor announced this vulnerability. |
| Vulnerable: |
NetBSD NetBSD 2.0.2 NetBSD NetBSD 2.0.1 NetBSD NetBSD 2.0 NetBSD NetBSD 1.6.2 NetBSD NetBSD 1.6.1 NetBSD NetBSD 1.6 beta NetBSD NetBSD 1.6 |
| Not Vulnerable: |
NetBSD NetBSD 2.0.3 |
Discussion
NetBSD Insecure Temporary File Creation Vulnerability
NetBSD creates temporary files in an insecure manner in the X build process. An attacker with local access could potentially exploit this issue to overwrite files in the context of the victim user.
Exploitation would most likely result in loss of data or a denial of service if critical files are overwritten in the attack. Other attacks may be possible as well.
NetBSD creates temporary files in an insecure manner in the X build process. An attacker with local access could potentially exploit this issue to overwrite files in the context of the victim user.
Exploitation would most likely result in loss of data or a denial of service if critical files are overwritten in the attack. Other attacks may be possible as well.
Exploit / POC
NetBSD Insecure Temporary File Creation Vulnerability
An exploit is not required.
An exploit is not required.
Solution / Fix
NetBSD Insecure Temporary File Creation Vulnerability
Solution:
The vendor has addressed this issue in NetBSD version 2.0.3. Users are advised to contact the vendor for details on obtaining the appropriate updates.
Solution:
The vendor has addressed this issue in NetBSD version 2.0.3. Users are advised to contact the vendor for details on obtaining the appropriate updates.
References
NetBSD Insecure Temporary File Creation Vulnerability
References:
References:
- NetBSD Homepage (NetBSD)
- NetBSD Security Advisory 2005-009 (NetBSD)