NetCitadel Firewall Builder Insecure Temporary File Creation Vulnerability
BID:30907
Info
NetCitadel Firewall Builder Insecure Temporary File Creation Vulnerability
| Bugtraq ID: | 30907 |
| Class: | Design Error |
| CVE: | |
| Remote: | No |
| Local: | Yes |
| Published: | Aug 24 2008 12:00AM |
| Updated: | Aug 29 2008 08:57PM |
| Credit: | Dmitry E. Oboukhov |
| Vulnerable: |
NetCitadel Firewall Builder 2.1.19 |
| Not Vulnerable: | |
Discussion
NetCitadel Firewall Builder Insecure Temporary File Creation Vulnerability
Firewall Builder creates temporary files in an insecure manner.
An attacker with local access could potentially exploit this issue to perform symbolic-link attacks, overwriting arbitrary files in the context of the affected application.
Successfully mounting a symlink attack may allow the attacker to delete or corrupt sensitive files, which may result in a denial of service. Other attacks may also be possible.
Firewall Builder 2.1.19 is vulnerable; other versions may also be affected.
Firewall Builder creates temporary files in an insecure manner.
An attacker with local access could potentially exploit this issue to perform symbolic-link attacks, overwriting arbitrary files in the context of the affected application.
Successfully mounting a symlink attack may allow the attacker to delete or corrupt sensitive files, which may result in a denial of service. Other attacks may also be possible.
Firewall Builder 2.1.19 is vulnerable; other versions may also be affected.
Exploit / POC
NetCitadel Firewall Builder Insecure Temporary File Creation Vulnerability
An attacker uses readily available commands to exploit this issue.
An attacker uses readily available commands to exploit this issue.
Solution / Fix
NetCitadel Firewall Builder Insecure Temporary File Creation Vulnerability
Solution:
Reportedly, vendor fixes are about to be released. Please see the references for more information.
Solution:
Reportedly, vendor fixes are about to be released. Please see the references for more information.
References
NetCitadel Firewall Builder Insecure Temporary File Creation Vulnerability
References:
References:
- Firewall Builder (NetCitadel)
- Debian Bug report logs - #496406 (Dmitry E. Oboukhov)