FireGPG Insecure Temporary File Creation Vulnerability
BID:31827
Info
FireGPG Insecure Temporary File Creation Vulnerability
| Bugtraq ID: | 31827 |
| Class: | Design Error |
| CVE: | |
| Remote: | No |
| Local: | Yes |
| Published: | Oct 20 2008 12:00AM |
| Updated: | Oct 21 2008 09:37PM |
| Credit: | Mike Benham |
| Vulnerable: |
FireGPG FireGPG 0.5.2 FireGPG FireGPG 0.4.7 FireGPG FireGPG 0.4.6 |
| Not Vulnerable: |
FireGPG FireGPG 0.6 |
Discussion
FireGPG Insecure Temporary File Creation Vulnerability
FireGPG creates temporary files in an insecure manner.
An attacker with local access could potentially exploit this issue to perform symbolic-link attacks, overwriting arbitrary files in the context of the affected application.
Successfully mounting a symlink attack may allow the attacker to obtain sensitive information, including passphrases and decrypted data. The attacker may also exploit this issue to delete or corrupt sensitive files, which may result in a denial of service. Other attacks may also be possible.
Versions prior to FireGPG 6.0 are affected.
FireGPG creates temporary files in an insecure manner.
An attacker with local access could potentially exploit this issue to perform symbolic-link attacks, overwriting arbitrary files in the context of the affected application.
Successfully mounting a symlink attack may allow the attacker to obtain sensitive information, including passphrases and decrypted data. The attacker may also exploit this issue to delete or corrupt sensitive files, which may result in a denial of service. Other attacks may also be possible.
Versions prior to FireGPG 6.0 are affected.
Exploit / POC
FireGPG Insecure Temporary File Creation Vulnerability
An attacker uses readily available commands to exploit this issue.
An attacker uses readily available commands to exploit this issue.
Solution / Fix
FireGPG Insecure Temporary File Creation Vulnerability
Solution:
The vendor has released an update to address this issue. Please see the references for more information.
Solution:
The vendor has released an update to address this issue. Please see the references for more information.
References
FireGPG Insecure Temporary File Creation Vulnerability
References:
References:
- FireGPG Homepage (FireGPG)
- FireGPG Passphrase And Cleartext Vulnerability (Mike Benham
)