PADL Software MigtrationTools Insecure Temporary File Creation Vulnerability
BID:15431
Info
PADL Software MigtrationTools Insecure Temporary File Creation Vulnerability
| Bugtraq ID: | 15431 |
| Class: | Race Condition Error |
| CVE: | |
| Remote: | No |
| Local: | Yes |
| Published: | Nov 15 2005 12:00AM |
| Updated: | Oct 02 2006 05:25PM |
| Credit: | This issue was discovered by Jason Hoover <[email protected]>. |
| Vulnerable: |
PADL Software MigrationTools 46 Debian Linux 3.1 |
| Not Vulnerable: | |
Discussion
PADL Software MigtrationTools Insecure Temporary File Creation Vulnerability
PADL Software MigrationTools creates temporary files in an insecure manner. An attacker with local access could potentially exploit this issue to obtain sensitive information in the context of the affected computer.
Exploitation would most likely result in loss of confidentiality or data. A denial of service could occur if critical files are overwritten in the attack. Other attacks may be possible as well.
MigrationTools version 46 is reported affected by this issue; other versions may also be affected.
PADL Software MigrationTools creates temporary files in an insecure manner. An attacker with local access could potentially exploit this issue to obtain sensitive information in the context of the affected computer.
Exploitation would most likely result in loss of confidentiality or data. A denial of service could occur if critical files are overwritten in the attack. Other attacks may be possible as well.
MigrationTools version 46 is reported affected by this issue; other versions may also be affected.
Exploit / POC
PADL Software MigtrationTools Insecure Temporary File Creation Vulnerability
An exploit is not required.
An exploit is not required.
Solution / Fix
PADL Software MigtrationTools Insecure Temporary File Creation Vulnerability
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected]:[email protected].
Please see the references for more information.
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected]:[email protected].
Please see the references for more information.
References
PADL Software MigtrationTools Insecure Temporary File Creation Vulnerability
References:
References:
- Debian Bug report logs - #338920 (Debian)
- MigrationTools Home Page (PADL Software)