Python 'move-faqwiz.sh' Insecure Temporary File Creation Vulnerability
BID:31184
Info
Python 'move-faqwiz.sh' Insecure Temporary File Creation Vulnerability
| Bugtraq ID: | 31184 |
| Class: | Design Error |
| CVE: | |
| Remote: | No |
| Local: | Yes |
| Published: | Sep 15 2008 12:00AM |
| Updated: | Apr 16 2015 06:14PM |
| Credit: | Jan Hauke Rahm |
| Vulnerable: |
RedHat Enterprise Linux WS 5 RedHat Enterprise Linux WS 4 RedHat Enterprise Linux ES 4 RedHat Enterprise Linux Desktop Workstation 5 client RedHat Enterprise Linux Desktop version 4 Red Hat Enterprise Linux Desktop 5 client Red Hat Enterprise Linux AS 4 Red Hat Enterprise Linux 5 Server Python Software Foundation Python 2.4.5 Python Software Foundation Python 2.4.4 -r14 Python Software Foundation Python 2.4.4 Python Software Foundation Python 2.4.3 Python Software Foundation Python 2.4.2 Python Software Foundation Python 2.4.1 Python Software Foundation Python 2.4 Python Software Foundation Python 2.3.6 Python Software Foundation Python 2.3.5 Python Software Foundation Python 2.3.4 Debian Linux 4.0 sparc Debian Linux 4.0 s/390 Debian Linux 4.0 powerpc Debian Linux 4.0 mipsel Debian Linux 4.0 mips Debian Linux 4.0 m68k Debian Linux 4.0 ia-64 Debian Linux 4.0 ia-32 Debian Linux 4.0 hppa Debian Linux 4.0 arm Debian Linux 4.0 amd64 Debian Linux 4.0 alpha Debian Linux 4.0 |
| Not Vulnerable: | |
Discussion
Python 'move-faqwiz.sh' Insecure Temporary File Creation Vulnerability
Python creates temporary files in an insecure manner.
An attacker with local access could potentially exploit this issue to perform symbolic-link attacks, overwriting arbitrary files in the context of the affected application.
Successfully mounting a symlink attack may allow the attacker to delete or corrupt sensitive files, which may result in a denial of service. Other attacks may also be possible.
Python 2.3.4 is vulnerable; other versions may also be affected.
Python creates temporary files in an insecure manner.
An attacker with local access could potentially exploit this issue to perform symbolic-link attacks, overwriting arbitrary files in the context of the affected application.
Successfully mounting a symlink attack may allow the attacker to delete or corrupt sensitive files, which may result in a denial of service. Other attacks may also be possible.
Python 2.3.4 is vulnerable; other versions may also be affected.
Exploit / POC
Python 'move-faqwiz.sh' Insecure Temporary File Creation Vulnerability
An attacker uses readily available commands to exploit this issue.
An attacker uses readily available commands to exploit this issue.
Solution / Fix
Python 'move-faqwiz.sh' Insecure Temporary File Creation Vulnerability
Solution:
Currently we are not aware of any vendor-supplied patches. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Solution:
Currently we are not aware of any vendor-supplied patches. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
References
Python 'move-faqwiz.sh' Insecure Temporary File Creation Vulnerability
References:
References:
- Bug 462326 - python: Generic FAQ wizard moving tool insecure auxiliary /tmp fi (Jan Lieskovsky)
- Debian Bug report logs - #498899 Unsecure use of temporary files (Jan Hauke Rahm)
- Python Homepage (Python Software Foundation)