Mon 'alert.d/test.alert' Insecure Temporary File Creation Vulnerability
BID:31597
Info
Mon 'alert.d/test.alert' Insecure Temporary File Creation Vulnerability
| Bugtraq ID: | 31597 |
| Class: | Design Error |
| CVE: |
CVE-2008-4477 |
| Remote: | No |
| Local: | Yes |
| Published: | Aug 24 2008 12:00AM |
| Updated: | Oct 17 2008 02:17PM |
| Credit: | Dmitry E. Oboukhov |
| Vulnerable: |
MandrakeSoft Corporate Server 3.0 x86_64 MandrakeSoft Corporate Server 3.0 Debian mon 0.99 Debian Linux 4.0 sparc Debian Linux 4.0 s/390 Debian Linux 4.0 powerpc Debian Linux 4.0 mipsel Debian Linux 4.0 mips Debian Linux 4.0 m68k Debian Linux 4.0 ia-64 Debian Linux 4.0 ia-32 Debian Linux 4.0 hppa Debian Linux 4.0 arm Debian Linux 4.0 amd64 Debian Linux 4.0 alpha Debian Linux 4.0 |
| Not Vulnerable: |
Debian mon 0.99.2-13 |
Discussion
Mon 'alert.d/test.alert' Insecure Temporary File Creation Vulnerability
The 'mon' tool creates temporary files in an insecure manner.
An attacker with local access could potentially exploit this issue to perform symbolic-link attacks, overwriting arbitrary files in the context of the affected application.
Successfully mounting a symlink attack may allow the attacker to delete or corrupt sensitive files, which may result in a denial of service. Other attacks may also be possible.
The 'mon' tool creates temporary files in an insecure manner.
An attacker with local access could potentially exploit this issue to perform symbolic-link attacks, overwriting arbitrary files in the context of the affected application.
Successfully mounting a symlink attack may allow the attacker to delete or corrupt sensitive files, which may result in a denial of service. Other attacks may also be possible.
Exploit / POC
Mon 'alert.d/test.alert' Insecure Temporary File Creation Vulnerability
An attacker uses readily available commands to exploit this issue.
An attacker uses readily available commands to exploit this issue.
Solution / Fix
Mon 'alert.d/test.alert' Insecure Temporary File Creation Vulnerability
Solution:
Vendor updates are available. Please see the references for more information.
Debian Linux 4.0 amd64
Debian Linux 4.0 ia-32
Debian Linux 4.0 arm
Debian Linux 4.0 hppa
Debian Linux 4.0 sparc
Debian Linux 4.0 s/390
Debian Linux 4.0 powerpc
Debian Linux 4.0 alpha
Debian Linux 4.0 mipsel
Debian Linux 4.0 ia-64
Debian Linux 4.0 mips
MandrakeSoft Corporate Server 3.0 x86_64
MandrakeSoft Corporate Server 3.0
Solution:
Vendor updates are available. Please see the references for more information.
Debian Linux 4.0 amd64
-
Debian mon_0.99.2-9+etch2_amd64.deb
http://security.debian.org/pool/updates/main/m/mon/mon_0.99.2-9+etch2_ amd64.deb
Debian Linux 4.0 ia-32
-
Debian mon_0.99.2-9+etch2_i386.deb
http://security.debian.org/pool/updates/main/m/mon/mon_0.99.2-9+etch2_ i386.deb
Debian Linux 4.0 arm
-
Debian mon_0.99.2-9+etch2_arm.deb
http://security.debian.org/pool/updates/main/m/mon/mon_0.99.2-9+etch2_ arm.deb
Debian Linux 4.0 hppa
-
Debian mon_0.99.2-9+etch2_hppa.deb
http://security.debian.org/pool/updates/main/m/mon/mon_0.99.2-9+etch2_ hppa.deb
Debian Linux 4.0 sparc
-
Debian mon_0.99.2-9+etch2_sparc.deb
http://security.debian.org/pool/updates/main/m/mon/mon_0.99.2-9+etch2_ sparc.deb
Debian Linux 4.0 s/390
-
Debian mon_0.99.2-9+etch2_s390.deb
http://security.debian.org/pool/updates/main/m/mon/mon_0.99.2-9+etch2_ s390.deb
Debian Linux 4.0 powerpc
-
Debian mon_0.99.2-9+etch2_powerpc.deb
http://security.debian.org/pool/updates/main/m/mon/mon_0.99.2-9+etch2_ powerpc.deb
Debian Linux 4.0 alpha
-
Debian mon_0.99.2-9+etch2_alpha.deb
http://security.debian.org/pool/updates/main/m/mon/mon_0.99.2-9+etch2_ alpha.deb
Debian Linux 4.0 mipsel
-
Debian mon_0.99.2-9+etch2_mipsel.deb
http://security.debian.org/pool/updates/main/m/mon/mon_0.99.2-9+etch2_ mipsel.deb
Debian Linux 4.0 ia-64
-
Debian mon_0.99.2-9+etch2_ia64.deb
http://security.debian.org/pool/updates/main/m/mon/mon_0.99.2-9+etch2_ ia64.deb
Debian Linux 4.0 mips
-
Debian mon_0.99.2-9+etch2_mips.deb
http://security.debian.org/pool/updates/main/m/mon/mon_0.99.2-9+etch2_ mips.deb
MandrakeSoft Corporate Server 3.0 x86_64
-
Mandriva mon-0.99.2-4.1.C30mdk.x86_64.rpm
http://www.mandriva.com/en/download/
MandrakeSoft Corporate Server 3.0
-
Mandriva mon-0.99.2-4.1.C30mdk.i586.rpm
http://www.mandriva.com/en/download/
References
Mon 'alert.d/test.alert' Insecure Temporary File Creation Vulnerability
References:
References:
- mon Homepage (Debian)
- The possibility of attack with the help of symlinks in some Debian packages (Dmitry E. Oboukhov)