Website Meta Language Multiple Local Insecure Temporary File Creation Vulnerabilities
BID:27685
Info
Website Meta Language Multiple Local Insecure Temporary File Creation Vulnerabilities
| Bugtraq ID: | 27685 |
| Class: | Design Error |
| CVE: |
CVE-2008-0666 CVE-2008-0665 |
| Remote: | No |
| Local: | Yes |
| Published: | Feb 04 2008 12:00AM |
| Updated: | Apr 28 2008 02:26PM |
| Credit: | Frank Lichtenheld <[email protected]> reported these issues. |
| Vulnerable: |
Website Meta Language Website Meta Language 2.0.11 Mandriva Linux Mandrake 2008.0 x86_64 Mandriva Linux Mandrake 2008.0 Mandriva Linux Mandrake 2007.1 x86_64 Mandriva Linux Mandrake 2007.1 Gentoo Linux Debian Linux 4.0 sparc Debian Linux 4.0 s/390 Debian Linux 4.0 powerpc Debian Linux 4.0 mipsel Debian Linux 4.0 mips Debian Linux 4.0 m68k Debian Linux 4.0 ia-64 Debian Linux 4.0 ia-32 Debian Linux 4.0 hppa Debian Linux 4.0 arm Debian Linux 4.0 amd64 Debian Linux 4.0 alpha Debian Linux 4.0 |
| Not Vulnerable: | |
Discussion
Website Meta Language Multiple Local Insecure Temporary File Creation Vulnerabilities
Website Meta Language is reportedly affected by multiple local vulnerabilities because it creates temporary files in an insecure way. These issues stem from a design error that causes the application to fail to verify the presence of a file before writing to it.
An attacker may leverage these issues to overwrite arbitrary files with the privileges of an unsuspecting user that activates a vulnerable application.
Website Meta Language 2.0.11 is affected by these vulnerabilities; other versions may also be affected.
Website Meta Language is reportedly affected by multiple local vulnerabilities because it creates temporary files in an insecure way. These issues stem from a design error that causes the application to fail to verify the presence of a file before writing to it.
An attacker may leverage these issues to overwrite arbitrary files with the privileges of an unsuspecting user that activates a vulnerable application.
Website Meta Language 2.0.11 is affected by these vulnerabilities; other versions may also be affected.
Exploit / POC
Website Meta Language Multiple Local Insecure Temporary File Creation Vulnerabilities
An attacker uses readily available commands to exploit the issues.
An attacker uses readily available commands to exploit the issues.
Solution / Fix
Website Meta Language Multiple Local Insecure Temporary File Creation Vulnerabilities
Solution:
Debian has provided a patch:
http://people.debian.org/~nion/nmu-diff/wml-2.0.11-3_2.0.11-3.1.patch
Please see the references for more information.
Solution:
Debian has provided a patch:
http://people.debian.org/~nion/nmu-diff/wml-2.0.11-3_2.0.11-3.1.patch
Please see the references for more information.
References
Website Meta Language Multiple Local Insecure Temporary File Creation Vulnerabilities
References:
References:
- Debian Bug report logs - #463907 (Frank Lichtenheld
) - Website Meta Language Home Page (Website Meta Language)