GNU gnump3d Insecure Temporary File Creation Vulnerability
BID:15497
Info
GNU gnump3d Insecure Temporary File Creation Vulnerability
| Bugtraq ID: | 15497 |
| Class: | Access Validation Error |
| CVE: |
CVE-2005-3349 CVE-2005-3349 |
| Remote: | No |
| Local: | Yes |
| Published: | Nov 04 2005 12:00AM |
| Updated: | Mar 19 2015 08:22AM |
| Credit: | The vendor disclosed this vulnerability. |
| Vulnerable: |
SuSE SUSE Linux Enterprise Server 9 SuSE SUSE Linux Enterprise Server 8 S.u.S.E. SuSE Linux Standard Server 8.0 S.u.S.E. SuSE Linux School Server for i386 S.u.S.E. SUSE LINUX Retail Solution 8.0 S.u.S.E. SuSE Linux Openexchange Server 4.0 S.u.S.E. Open-Enterprise-Server 9.0 S.u.S.E. Novell Linux Desktop 9.0 S.u.S.E. Linux Professional 10.0 OSS S.u.S.E. Linux Professional 9.3 x86_64 S.u.S.E. Linux Professional 9.3 S.u.S.E. Linux Professional 9.2 x86_64 S.u.S.E. Linux Professional 9.2 S.u.S.E. Linux Professional 9.1 x86_64 S.u.S.E. Linux Professional 9.1 S.u.S.E. Linux Professional 9.0 x86_64 S.u.S.E. Linux Professional 9.0 S.u.S.E. Linux Professional 8.2 S.u.S.E. Linux Personal 10.0 OSS S.u.S.E. Linux Personal 9.3 x86_64 S.u.S.E. Linux Personal 9.3 S.u.S.E. Linux Personal 9.2 x86_64 S.u.S.E. Linux Personal 9.2 S.u.S.E. Linux Personal 9.1 x86_64 S.u.S.E. Linux Personal 9.1 S.u.S.E. Linux Personal 9.0 x86_64 S.u.S.E. Linux Personal 9.0 S.u.S.E. Linux Personal 8.2 S.u.S.E. Linux Desktop 1.0 GNU gnump3d 2.9.7 GNU gnump3d 2.9.6 GNU gnump3d 2.9.5 GNU gnump3d 2.9.4 GNU gnump3d 2.9.3 GNU gnump3d 2.9.2 GNU gnump3d 2.9.1 GNU gnump3d 2.9 Debian Linux 3.1 sparc Debian Linux 3.1 s/390 Debian Linux 3.1 ppc Debian Linux 3.1 mipsel Debian Linux 3.1 mips Debian Linux 3.1 m68k Debian Linux 3.1 ia-64 Debian Linux 3.1 ia-32 Debian Linux 3.1 hppa Debian Linux 3.1 arm Debian Linux 3.1 amd64 Debian Linux 3.1 alpha Debian Linux 3.1 Debian Linux 3.0 sparc Debian Linux 3.0 s/390 Debian Linux 3.0 ppc Debian Linux 3.0 mipsel Debian Linux 3.0 mips Debian Linux 3.0 m68k Debian Linux 3.0 ia-64 Debian Linux 3.0 ia-32 Debian Linux 3.0 hppa Debian Linux 3.0 arm Debian Linux 3.0 alpha Debian Linux 3.0 Acme thttpd 2.23 b1 Acme thttpd 2.21 b |
| Not Vulnerable: |
GNU gnump3d 2.9.8 |
Discussion
GNU gnump3d Insecure Temporary File Creation Vulnerability
GNU gnump3d creates temporary files in an insecure manner.
An attacker with local access could potentially exploit this issue to overwrite files in the context of the Web server process.
Exploitation would most likely result in loss of data or a denial of service if critical files are overwritten in the attack. Other attacks may be possible as well.
GNU gnump3d creates temporary files in an insecure manner.
An attacker with local access could potentially exploit this issue to overwrite files in the context of the Web server process.
Exploitation would most likely result in loss of data or a denial of service if critical files are overwritten in the attack. Other attacks may be possible as well.
Exploit / POC
GNU gnump3d Insecure Temporary File Creation Vulnerability
An exploit is not required.
An exploit is not required.
Solution / Fix
GNU gnump3d Insecure Temporary File Creation Vulnerability
Solution:
Debian has released advisory DSA 901-1 and fixes to address this issue. Please see the referenced advisory for further information.
Gentoo has released an advisory to address this issue. Gentoo users can apply fixes by running the following commands as the superuser:
emerge --sync
emerge --ask --oneshot --verbose ">=media-sound/gnump3d-2.9.7-r1"
SUSE advisory SUSE-SR:2005:028 is available to address various issues. Please see the referenced advisory for more information.
The vendor has addressed this issue in gnump3d version 2.9.8:
GNU gnump3d 2.9
GNU gnump3d 2.9.1
GNU gnump3d 2.9.2
GNU gnump3d 2.9.3
GNU gnump3d 2.9.4
GNU gnump3d 2.9.5
GNU gnump3d 2.9.6
GNU gnump3d 2.9.7
Solution:
Debian has released advisory DSA 901-1 and fixes to address this issue. Please see the referenced advisory for further information.
Gentoo has released an advisory to address this issue. Gentoo users can apply fixes by running the following commands as the superuser:
emerge --sync
emerge --ask --oneshot --verbose ">=media-sound/gnump3d-2.9.7-r1"
SUSE advisory SUSE-SR:2005:028 is available to address various issues. Please see the referenced advisory for more information.
The vendor has addressed this issue in gnump3d version 2.9.8:
GNU gnump3d 2.9
-
GNU gnump3d-2.9.8.tar.gz
http://savannah.gnu.org/download/gnump3d/gnump3d-2.9.8.tar.gz
GNU gnump3d 2.9.1
-
GNU gnump3d-2.9.8.tar.gz
http://savannah.gnu.org/download/gnump3d/gnump3d-2.9.8.tar.gz
GNU gnump3d 2.9.2
-
GNU gnump3d-2.9.8.tar.gz
http://savannah.gnu.org/download/gnump3d/gnump3d-2.9.8.tar.gz
GNU gnump3d 2.9.3
-
GNU gnump3d-2.9.8.tar.gz
http://savannah.gnu.org/download/gnump3d/gnump3d-2.9.8.tar.gz
GNU gnump3d 2.9.4
-
GNU gnump3d-2.9.8.tar.gz
http://savannah.gnu.org/download/gnump3d/gnump3d-2.9.8.tar.gz
GNU gnump3d 2.9.5
-
GNU gnump3d-2.9.8.tar.gz
http://savannah.gnu.org/download/gnump3d/gnump3d-2.9.8.tar.gz
GNU gnump3d 2.9.6
-
GNU gnump3d-2.9.8.tar.gz
http://savannah.gnu.org/download/gnump3d/gnump3d-2.9.8.tar.gz
GNU gnump3d 2.9.7
-
GNU gnump3d-2.9.8.tar.gz
http://savannah.gnu.org/download/gnump3d/gnump3d-2.9.8.tar.gz
References
GNU gnump3d Insecure Temporary File Creation Vulnerability
References:
References: