Horde and Imp Temporary File Vulnerability
BID:3066
Info
Horde and Imp Temporary File Vulnerability
| Bugtraq ID: | 3066 |
| Class: | Race Condition Error |
| CVE: | |
| Remote: | No |
| Local: | Yes |
| Published: | Jul 13 2001 12:00AM |
| Updated: | Jul 13 2001 12:00AM |
| Credit: | This vulnerability was posted to BugTraq with a Caldera Open Linux advisory by Support Info <[email protected]> on July 13th 2001. Additional credit goes to Jarno Huuskonen <[email protected]> for discovering and reporting temporary file problems in |
| Vulnerable: |
Horde Project IMP 2.2.5 Horde Project IMP 2.2.4 Horde Project IMP 2.2.3 Horde Project IMP 2.2.2 Horde Project IMP 2.2.1 Horde Project IMP 2.2 Horde Project IMP 2.0 Horde Project Horde 1.2.1 Horde Project Horde 1.2 |
| Not Vulnerable: | |
Discussion
Horde and Imp Temporary File Vulnerability
Imp is a powerful web-based mail interface/client developed by members of the Horde project. Horde Application Framework provides support for dealing with things like preferences, compression, browser detection, connection tracking, etc.
Imp creates temporary files insecurely. While some temporary file issues have been patched in Imp, there are still multiple instances where the files are created insecurely.
This issue can be exploited with symlink attacks by local attackers. The minimum effect of exploitation would be loss of critical data in overwritten files, and a potential for denial on services depending on which files are attacked. Worse than that is that local attackers may be able to elevate privileges on the host if they find a way to supply input that is written to files in symlink attacks.
Imp is a powerful web-based mail interface/client developed by members of the Horde project. Horde Application Framework provides support for dealing with things like preferences, compression, browser detection, connection tracking, etc.
Imp creates temporary files insecurely. While some temporary file issues have been patched in Imp, there are still multiple instances where the files are created insecurely.
This issue can be exploited with symlink attacks by local attackers. The minimum effect of exploitation would be loss of critical data in overwritten files, and a potential for denial on services depending on which files are attacked. Worse than that is that local attackers may be able to elevate privileges on the host if they find a way to supply input that is written to files in symlink attacks.
Solution / Fix
Horde and Imp Temporary File Vulnerability
Solution:
Caldera has released an upgraded version which addresses some of the temporary file issues.
Horde Project Horde 1.2
Horde Project Horde 1.2.1
Horde Project IMP 2.0
Horde Project IMP 2.2
Horde Project IMP 2.2.2
Horde Project IMP 2.2.3
Horde Project IMP 2.2.4
Solution:
Caldera has released an upgraded version which addresses some of the temporary file issues.
Horde Project Horde 1.2
-
Caldera OpenLinux Server 3.1 horde-1.2.4-6.i386.rpm
ftp://ftp.caldera.com/pub/updates/OpenLinux/3.1/Server/current/RPMS/ho rde-1.2.4-6.i386.rpm
Horde Project Horde 1.2.1
-
Caldera OpenLinux Server 3.1 horde-1.2.4-6.i386.rpm
ftp://ftp.caldera.com/pub/updates/OpenLinux/3.1/Server/current/RPMS/ho rde-1.2.4-6.i386.rpm
Horde Project IMP 2.0
-
Caldera OpenLinux Server 3.1 imp-2.2.5-2.i386.rpm
ftp://ftp.caldera.com/pub/updates/OpenLinux/3.1/Server/current/RPMS/im p-2.2.5-2.i386.rpm
Horde Project IMP 2.2
-
Caldera OpenLinux Server 3.1 imp-2.2.5-2.i386.rpm
ftp://ftp.caldera.com/pub/updates/OpenLinux/3.1/Server/current/RPMS/im p-2.2.5-2.i386.rpm
Horde Project IMP 2.2.2
-
Caldera OpenLinux Server 3.1 imp-2.2.5-2.i386.rpm
ftp://ftp.caldera.com/pub/updates/OpenLinux/3.1/Server/current/RPMS/im p-2.2.5-2.i386.rpm
Horde Project IMP 2.2.3
-
Caldera OpenLinux Server 3.1 imp-2.2.5-2.i386.rpm
ftp://ftp.caldera.com/pub/updates/OpenLinux/3.1/Server/current/RPMS/im p-2.2.5-2.i386.rpm
Horde Project IMP 2.2.4
-
Caldera OpenLinux Server 3.1 imp-2.2.5-2.i386.rpm
ftp://ftp.caldera.com/pub/updates/OpenLinux/3.1/Server/current/RPMS/im p-2.2.5-2.i386.rpm