EIX Insecure Temporary File Creation Vulnerability
BID:15541
Info
EIX Insecure Temporary File Creation Vulnerability
| Bugtraq ID: | 15541 |
| Class: | Race Condition Error |
| CVE: | |
| Remote: | No |
| Local: | Yes |
| Published: | Nov 23 2005 12:00AM |
| Updated: | Nov 23 2005 12:00AM |
| Credit: | Eric Romang is credited with the discovery of this vulnerability. |
| Vulnerable: |
Gentoo Linux eix eix 0.5 .0-beta eix eix 0.3 .0-r1 |
| Not Vulnerable: |
eix eix 0.5 .0-pre2 eix eix 0.3 .0-r2 |
Discussion
EIX Insecure Temporary File Creation Vulnerability
eix creates temporary files in an insecure manner. An attacker with local access could potentially exploit this issue to obtain sensitive information in the context of the user running the application.
Exploitation would most likely result in loss of confidentiality, data or a denial of service if critical files are overwritten in the attack. Other attacks may be possible as well.
eix creates temporary files in an insecure manner. An attacker with local access could potentially exploit this issue to obtain sensitive information in the context of the user running the application.
Exploitation would most likely result in loss of confidentiality, data or a denial of service if critical files are overwritten in the attack. Other attacks may be possible as well.
Exploit / POC
EIX Insecure Temporary File Creation Vulnerability
An exploit is not required.
An exploit is not required.
Solution / Fix
EIX Insecure Temporary File Creation Vulnerability
Solution:
Gentoo Linux has released security advisory GLSA 200511-19 addressing this issue. Gentoo recommends all eix users should upgrade to the latest version:
# emerge --sync
# emerge --ask --oneshot --verbose app-portage/eix
The vendor has addressed this issue in the latest available release.
Solution:
Gentoo Linux has released security advisory GLSA 200511-19 addressing this issue. Gentoo recommends all eix users should upgrade to the latest version:
# emerge --sync
# emerge --ask --oneshot --verbose app-portage/eix
The vendor has addressed this issue in the latest available release.
References
EIX Insecure Temporary File Creation Vulnerability
References:
References:
- CVE-2015-7513 Kernel: kvm: divide by zero issue leads to DoS (Prasad J Pandit)
- eix Homepage (eix)
- fix http://bugs.gentoo.org/show_bug.cgi?id=112061 (eix)