Roxio Toast DejaVu Component Insecure Temporary File Handling Vulnerability
BID:19955
CVE-2006-4801 |Info
Roxio Toast DejaVu Component Insecure Temporary File Handling Vulnerability
| Bugtraq ID: | 19955 |
| Class: | Race Condition Error |
| CVE: | |
| Remote: | No |
| Local: | Yes |
| Published: | Sep 11 2006 12:00AM |
| Updated: | Sep 12 2006 06:22PM |
| Credit: | Netragard, L.L.C is credited with the discovery of this vulnerability. |
| Vulnerable: |
Roxio Toast 7.Titanium |
| Not Vulnerable: | |
Discussion
Roxio Toast DejaVu Component Insecure Temporary File Handling Vulnerability
Roxio Toast handles temporary files in an insecure manner.
This issue allows local attackers to gain superuser privileges, resulting in a complete compromise of affected computers.
This issue affects the DejaVu component that is installed by default in a standard installation of the vulnerable application. DejaVu is a third-party component that is maintained by Propaganda Productions. Roxio Toast version 7 Titanium includes the vulnerable component; other versions may also be affected.
Roxio Toast handles temporary files in an insecure manner.
This issue allows local attackers to gain superuser privileges, resulting in a complete compromise of affected computers.
This issue affects the DejaVu component that is installed by default in a standard installation of the vulnerable application. DejaVu is a third-party component that is maintained by Propaganda Productions. Roxio Toast version 7 Titanium includes the vulnerable component; other versions may also be affected.
Exploit / POC
Roxio Toast DejaVu Component Insecure Temporary File Handling Vulnerability
Currently we are not aware of any exploits for this issue. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected]
Currently we are not aware of any exploits for this issue. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected]
Solution / Fix
Roxio Toast DejaVu Component Insecure Temporary File Handling Vulnerability
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected]:[email protected].
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected]:[email protected].
References
Roxio Toast DejaVu Component Insecure Temporary File Handling Vulnerability
References:
References:
- NETRAGARD-20060624 - Race Condition Explpoitation in Deja Vu (Netragard, L.L.C)
- Roxio Homepage (Roxio)