GSAMBAD Insecure Temporary File Creation Vulnerability
BID:24717
Info
GSAMBAD Insecure Temporary File Creation Vulnerability
| Bugtraq ID: | 24717 |
| Class: | Race Condition Error |
| CVE: |
CVE-2007-2838 |
| Remote: | No |
| Local: | Yes |
| Published: | Jul 01 2007 12:00AM |
| Updated: | Jul 02 2007 12:08PM |
| Credit: | Steve Kemp from the Debian Security Audit project discovered this issue. |
| Vulnerable: |
GSAMBAD GSAMBAD 0.1.6 GSAMBAD GSAMBAD 0.1.5 GSAMBAD GSAMBAD 0.1.4 Debian Linux 4.0 sparc Debian Linux 4.0 s/390 Debian Linux 4.0 powerpc Debian Linux 4.0 mipsel Debian Linux 4.0 mips Debian Linux 4.0 m68k Debian Linux 4.0 ia-64 Debian Linux 4.0 ia-32 Debian Linux 4.0 hppa Debian Linux 4.0 arm Debian Linux 4.0 amd64 Debian Linux 4.0 alpha Debian Linux 4.0 |
| Not Vulnerable: | |
Discussion
GSAMBAD Insecure Temporary File Creation Vulnerability
GSAMBAD creates temporary files in an insecure manner.
An attacker with local access could potentially exploit this issue to perform symlink attacks, overwriting arbitrary files in the context of the affected application.
An attacker may leverage this issue to corrupt or overwrite arbitrary files with the privileges of an unsuspecting user that activated the affected application. Reportedly, attackers can exploit this issue to escalate privileges.
All versions of GSAMBAD are considered to be vulnerable to this issue.
GSAMBAD creates temporary files in an insecure manner.
An attacker with local access could potentially exploit this issue to perform symlink attacks, overwriting arbitrary files in the context of the affected application.
An attacker may leverage this issue to corrupt or overwrite arbitrary files with the privileges of an unsuspecting user that activated the affected application. Reportedly, attackers can exploit this issue to escalate privileges.
All versions of GSAMBAD are considered to be vulnerable to this issue.
Exploit / POC
GSAMBAD Insecure Temporary File Creation Vulnerability
An exploit is not required as an attacker can manually carry out this attack.
An exploit is not required as an attacker can manually carry out this attack.
Solution / Fix
GSAMBAD Insecure Temporary File Creation Vulnerability
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: mailto:[email protected].
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: mailto:[email protected].