pam_mount Insecure Temporary File Creation Vulnerability
BID:32374
Info
pam_mount Insecure Temporary File Creation Vulnerability
| Bugtraq ID: | 32374 |
| Class: | Design Error |
| CVE: |
CVE-2008-5138 |
| Remote: | No |
| Local: | Yes |
| Published: | Aug 14 2008 12:00AM |
| Updated: | Mar 03 2009 05:46PM |
| Credit: | Dmitry E. Oboukhov |
| Vulnerable: |
SuSE SUSE Linux Enterprise Server 9 SuSE SUSE Linux Enterprise Server 10 S.u.S.E. openSUSE 11.1 S.u.S.E. openSUSE 11.0 S.u.S.E. openSUSE 10.3 pam_mount pam_mount 0.43 Mandriva Linux Mandrake 2009.0 x86_64 Mandriva Linux Mandrake 2009.0 Mandriva Linux Mandrake 2008.1 x86_64 Mandriva Linux Mandrake 2008.1 Mandriva Linux Mandrake 2008.0 x86_64 Mandriva Linux Mandrake 2008.0 MandrakeSoft Corporate Server 4.0 x86_64 MandrakeSoft Corporate Server 4.0 |
| Not Vulnerable: | |
Discussion
pam_mount Insecure Temporary File Creation Vulnerability
The 'pam_mount' module creates temporary files in an insecure manner.
An attacker with local access could perform symbolic-link attacks, overwriting arbitrary files in the context of the affected application.
Successfully mounting a symlink attack may allow the attacker to delete or corrupt sensitive files, which may result in a denial of service. Other attacks may also be possible.
This issue affects pam_mount 0.43; other versions may also be affected.
The 'pam_mount' module creates temporary files in an insecure manner.
An attacker with local access could perform symbolic-link attacks, overwriting arbitrary files in the context of the affected application.
Successfully mounting a symlink attack may allow the attacker to delete or corrupt sensitive files, which may result in a denial of service. Other attacks may also be possible.
This issue affects pam_mount 0.43; other versions may also be affected.
Exploit / POC
pam_mount Insecure Temporary File Creation Vulnerability
An attacker uses readily available commands to launch attacks.
An attacker uses readily available commands to launch attacks.
Solution / Fix
pam_mount Insecure Temporary File Creation Vulnerability
Solution:
The vendor has released fixes to address this issue. Please see the references for more information.
Mandriva Linux Mandrake 2009.0 x86_64
Mandriva Linux Mandrake 2008.1 x86_64
Mandriva Linux Mandrake 2008.0 x86_64
Mandriva Linux Mandrake 2008.1
Mandriva Linux Mandrake 2008.0
Mandriva Linux Mandrake 2009.0
MandrakeSoft Corporate Server 4.0
MandrakeSoft Corporate Server 4.0 x86_64
Solution:
The vendor has released fixes to address this issue. Please see the references for more information.
Mandriva Linux Mandrake 2009.0 x86_64
-
Mandriva pam_mount-0.48-1.2mdv2009.0.x86_64.rpm
http://www.mandriva.com/en/download/
Mandriva Linux Mandrake 2008.1 x86_64
-
Mandriva pam_mount-0.33-2.5mdv2008.1.x86_64.rpm
http://www.mandriva.com/en/download/
Mandriva Linux Mandrake 2008.0 x86_64
-
Mandriva pam_mount-0.17-1.3mdv2008.0.x86_64.rpm
http://www.mandriva.com/en/download/ -
Mandriva pam_mount-devel-0.17-1.3mdv2008.0.x86_64.rpm
http://www.mandriva.com/en/download/
Mandriva Linux Mandrake 2008.1
-
Mandriva pam_mount-0.33-2.5mdv2008.1.i586.rpm
http://www.mandriva.com/en/download/
Mandriva Linux Mandrake 2008.0
-
Mandriva pam_mount-0.17-1.3mdv2008.0.i586.rpm
http://www.mandriva.com/en/download/ -
Mandriva pam_mount-devel-0.17-1.3mdv2008.0.i586.rpm
http://www.mandriva.com/en/download/
Mandriva Linux Mandrake 2009.0
-
Mandriva pam_mount-0.48-1.2mdv2009.0.i586.rpm
http://www.mandriva.com/en/download/
MandrakeSoft Corporate Server 4.0
-
Mandriva pam_mount-0.10.0-5.3.20060mlcs4.i586.rpm
http://www.mandriva.com/en/download/ -
Mandriva pam_mount-devel-0.10.0-5.3.20060mlcs4.i586.rpm
http://www.mandriva.com/en/download/
MandrakeSoft Corporate Server 4.0 x86_64
-
Mandriva pam_mount-0.10.0-5.3.20060mlcs4.x86_64.rpm
http://www.mandriva.com/en/download/ -
Mandriva pam_mount-devel-0.10.0-5.3.20060mlcs4.x86_64.rpm
http://www.mandriva.com/en/download/
References
pam_mount Insecure Temporary File Creation Vulnerability
References:
References: