feynmf feynmf.pl Insecure Temporary File Creation Vulnerability
BID:26507
Info
feynmf feynmf.pl Insecure Temporary File Creation Vulnerability
| Bugtraq ID: | 26507 |
| Class: | Race Condition Error |
| CVE: |
CVE-2007-5940 |
| Remote: | No |
| Local: | Yes |
| Published: | Nov 20 2007 12:00AM |
| Updated: | Nov 20 2007 11:44PM |
| Credit: | Kevin B. McCarty discovered this vulnerability. |
| Vulnerable: |
Gentoo dev-text/feynmf 1.08-r1 feynmf feynmf 1.08 |
| Not Vulnerable: | |
Discussion
feynmf feynmf.pl Insecure Temporary File Creation Vulnerability
The 'feynmf' tool is prone to a security vulnerability because it creates temporary files in an insecure manner.
An attacker with local access could potentially exploit this issue to perform symlink attacks, overwriting arbitrary files in the context of the affected application.
Successfully mounting a symlink attack may allow the attacker to overwrite or corrupt sensitive files, which may result in a denial of service. Other attacks may also be possible.
This issue affects feynmf 1.08; other versions may also be vulnerable.
The 'feynmf' tool is prone to a security vulnerability because it creates temporary files in an insecure manner.
An attacker with local access could potentially exploit this issue to perform symlink attacks, overwriting arbitrary files in the context of the affected application.
Successfully mounting a symlink attack may allow the attacker to overwrite or corrupt sensitive files, which may result in a denial of service. Other attacks may also be possible.
This issue affects feynmf 1.08; other versions may also be vulnerable.
Exploit / POC
feynmf feynmf.pl Insecure Temporary File Creation Vulnerability
An attacker uses readily available commands to exploit the issue.
An attacker uses readily available commands to exploit the issue.
Solution / Fix
feynmf feynmf.pl Insecure Temporary File Creation Vulnerability
Solution:
A patch that addresses this issue is available. Please see the references for more information.
Gentoo dev-text/feynmf 1.08-r1
Solution:
A patch that addresses this issue is available. Please see the references for more information.
Gentoo dev-text/feynmf 1.08-r1
-
Gentoo feynmf-1.08-tempfile.patch
http://bugs.gentoo.org/attachment.cgi?id=135319
References
feynmf feynmf.pl Insecure Temporary File Creation Vulnerability
References:
References: