Claws Mail Insecure Temporary File Creation Vulnerability
BID:26676
Info
Claws Mail Insecure Temporary File Creation Vulnerability
| Bugtraq ID: | 26676 |
| Class: | Race Condition Error |
| CVE: |
CVE-2007-6208 |
| Remote: | No |
| Local: | Yes |
| Published: | Dec 03 2007 12:00AM |
| Updated: | Mar 19 2015 09:40AM |
| Credit: | Nico Golde <[email protected]> reported this vulnerability. |
| Vulnerable: |
Gentoo Linux Debian Linux 3.1 sparc Debian Linux 3.1 s/390 Debian Linux 3.1 ppc Debian Linux 3.1 mipsel Debian Linux 3.1 mips Debian Linux 3.1 m68k Debian Linux 3.1 ia-64 Debian Linux 3.1 ia-32 Debian Linux 3.1 hppa Debian Linux 3.1 arm Debian Linux 3.1 amd64 Debian Linux 3.1 alpha Debian Linux 3.1 Debian Linux 4.0 sparc Debian Linux 4.0 s/390 Debian Linux 4.0 powerpc Debian Linux 4.0 mipsel Debian Linux 4.0 mips Debian Linux 4.0 m68k Debian Linux 4.0 ia-64 Debian Linux 4.0 ia-32 Debian Linux 4.0 hppa Debian Linux 4.0 arm Debian Linux 4.0 amd64 Debian Linux 4.0 alpha Debian Linux 4.0 Claws Mail Claws Mail 3.1 Claws Mail Claws Mail 3.0.2 |
| Not Vulnerable: | |
Discussion
Claws Mail Insecure Temporary File Creation Vulnerability
Claws Mail is prone to a security vulnerability because it creates temporary files in an insecure manner.
An attacker with local access could potentially exploit this issue to perform symlink attacks, overwriting arbitrary files in the context of the affected application.
Successfully mounting a symlink attack may allow the attacker to delete or corrupt sensitive files, which may result in a denial of service. Other attacks may also be possible.
This issue affects Claws Mail 3.1.0; other versions may also be vulnerable.
Claws Mail is prone to a security vulnerability because it creates temporary files in an insecure manner.
An attacker with local access could potentially exploit this issue to perform symlink attacks, overwriting arbitrary files in the context of the affected application.
Successfully mounting a symlink attack may allow the attacker to delete or corrupt sensitive files, which may result in a denial of service. Other attacks may also be possible.
This issue affects Claws Mail 3.1.0; other versions may also be vulnerable.
Exploit / POC
Claws Mail Insecure Temporary File Creation Vulnerability
An attacker uses readily available commands to exploit the issue.
An attacker uses readily available commands to exploit the issue.
Solution / Fix
Claws Mail Insecure Temporary File Creation Vulnerability
Solution:
Please see the referenced advisories for details on obtaining and applying the appropriate updates.
Solution:
Please see the referenced advisories for details on obtaining and applying the appropriate updates.
References
Claws Mail Insecure Temporary File Creation Vulnerability
References:
References:
- Claws Mail Home Page (Claws Mail)
- Debian Bug report logs - #454089 (Nico Golde
)