XWine Printing Insecure Temporary File Creation Vulnerability
BID:28049
Info
XWine Printing Insecure Temporary File Creation Vulnerability
| Bugtraq ID: | 28049 |
| Class: | Design Error |
| CVE: |
CVE-2008-0930 |
| Remote: | No |
| Local: | Yes |
| Published: | Feb 26 2008 12:00AM |
| Updated: | Mar 20 2008 09:00PM |
| Credit: | Steve Kemp from Debian disclosed this vulnerability. |
| Vulnerable: |
Debian Linux 4.0 sparc Debian Linux 4.0 s/390 Debian Linux 4.0 powerpc Debian Linux 4.0 mipsel Debian Linux 4.0 mips Debian Linux 4.0 m68k Debian Linux 4.0 ia-64 Debian Linux 4.0 ia-32 Debian Linux 4.0 hppa Debian Linux 4.0 arm Debian Linux 4.0 amd64 Debian Linux 4.0 alpha Debian Linux 4.0 Darken33 XWine 1.0.1 |
| Not Vulnerable: | |
Discussion
XWine Printing Insecure Temporary File Creation Vulnerability
XWine is prone to a security vulnerability because it creates temporary files in an insecure manner.
An attacker with local access could potentially exploit this issue to perform symlink attacks, overwriting arbitrary files in the context of the affected application.
Successfully mounting a symlink attack may allow the attacker to overwrite or corrupt sensitive files, which may result in a denial of service. Other attacks may also be possible.
This issue affects XWine 1.0.1; other versions may also be vulnerable.
XWine is prone to a security vulnerability because it creates temporary files in an insecure manner.
An attacker with local access could potentially exploit this issue to perform symlink attacks, overwriting arbitrary files in the context of the affected application.
Successfully mounting a symlink attack may allow the attacker to overwrite or corrupt sensitive files, which may result in a denial of service. Other attacks may also be possible.
This issue affects XWine 1.0.1; other versions may also be vulnerable.
Exploit / POC
XWine Printing Insecure Temporary File Creation Vulnerability
An attacker uses standard commands to exploit the issue.
An attacker uses standard commands to exploit the issue.
Solution / Fix
XWine Printing Insecure Temporary File Creation Vulnerability
Solution:
Debian has issued an advisory and updates. Please see the referenced advisory for more information.
Solution:
Debian has issued an advisory and updates. Please see the referenced advisory for more information.
References
XWine Printing Insecure Temporary File Creation Vulnerability
References:
References:
- Overview of xwine source package (Debian)
- Vendor Homepage (Darken33)