Ogle DVD Player Insecure Temporary File Creation Vulnerabilities
BID:30926
Info
Ogle DVD Player Insecure Temporary File Creation Vulnerabilities
| Bugtraq ID: | 30926 |
| Class: | Design Error |
| CVE: |
CVE-2008-4976 |
| Remote: | No |
| Local: | Yes |
| Published: | Aug 29 2008 12:00AM |
| Updated: | Apr 16 2015 05:55PM |
| Credit: | Dmitry E. Oboukhov |
| Vulnerable: |
Ogle Ogle DVD Player 0.9.2 Debian Linux 4.0 sparc Debian Linux 4.0 s/390 Debian Linux 4.0 powerpc Debian Linux 4.0 mipsel Debian Linux 4.0 mips Debian Linux 4.0 m68k Debian Linux 4.0 ia-64 Debian Linux 4.0 ia-32 Debian Linux 4.0 hppa Debian Linux 4.0 arm Debian Linux 4.0 amd64 Debian Linux 4.0 alpha Debian Linux 4.0 |
| Not Vulnerable: | |
Discussion
Ogle DVD Player Insecure Temporary File Creation Vulnerabilities
Ogle DVD Player creates temporary files in an insecure manner.
An attacker with local access could potentially exploit these issues to perform symbolic-link attacks, overwriting arbitrary files in the context of the affected application.
Successfully mounting a symlink attack may allow the attacker to delete or corrupt sensitive files, which may result in a denial of service. Other attacks may also be possible.
Ogle 0.9.2 is vulnerable; other versions may also be affected.
Ogle DVD Player creates temporary files in an insecure manner.
An attacker with local access could potentially exploit these issues to perform symbolic-link attacks, overwriting arbitrary files in the context of the affected application.
Successfully mounting a symlink attack may allow the attacker to delete or corrupt sensitive files, which may result in a denial of service. Other attacks may also be possible.
Ogle 0.9.2 is vulnerable; other versions may also be affected.
Exploit / POC
Ogle DVD Player Insecure Temporary File Creation Vulnerabilities
An attacker uses readily available commands to exploit these issues.
An attacker uses readily available commands to exploit these issues.
Solution / Fix
Ogle DVD Player Insecure Temporary File Creation Vulnerabilities
Solution:
Currently we are not aware of any vendor-supplied patches. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Solution:
Currently we are not aware of any vendor-supplied patches. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
References
Ogle DVD Player Insecure Temporary File Creation Vulnerabilities
References:
References:
- #496425 - The possibility of attack with the help of symlinks in some Debian pac (Dmitry E. Oboukhov)
- Insecure tmp files in Debian packages (Dmitry E. Oboukhov)
- Ogle DVD Player Homepage (Ogle)