SCO OpenServer vi Insecure Temporary File Creation Vulnerability
BID:2752
Info
SCO OpenServer vi Insecure Temporary File Creation Vulnerability
| Bugtraq ID: | 2752 |
| Class: | Race Condition Error |
| CVE: | |
| Remote: | No |
| Local: | Yes |
| Published: | May 22 2001 12:00AM |
| Updated: | May 22 2001 12:00AM |
| Credit: | Reported to Bugtraq by Richard Johnson <[email protected]> on May 22, 2001. |
| Vulnerable: |
SCO Open Server 5.0.6 SCO Open Server 5.0.5 SCO Open Server 5.0.4 SCO Open Server 5.0.3 SCO Open Server 5.0.2 SCO Open Server 5.0.1 SCO Open Server 5.0 |
| Not Vulnerable: | |
Discussion
SCO OpenServer vi Insecure Temporary File Creation Vulnerability
An insecure temporary file creation vulnerability exists in the implementation of the vi editor included with some versions of SCO OpenServer.
The editor creates temporary files in /tmp without checking if the file already exists, using easily predictible names. As a result, it may be possible for a malicious user with local access to a host to cause local files to be overwritten, using a symbolic link attack.
An insecure temporary file creation vulnerability exists in the implementation of the vi editor included with some versions of SCO OpenServer.
The editor creates temporary files in /tmp without checking if the file already exists, using easily predictible names. As a result, it may be possible for a malicious user with local access to a host to cause local files to be overwritten, using a symbolic link attack.
Exploit / POC
SCO OpenServer vi Insecure Temporary File Creation Vulnerability
Currently the SecurityFocus staff are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Currently the SecurityFocus staff are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
References
SCO OpenServer vi Insecure Temporary File Creation Vulnerability
References:
References: