Netscape 6 Temp File Symbolic Link Vulnerability
BID:3243
Info
Netscape 6 Temp File Symbolic Link Vulnerability
| Bugtraq ID: | 3243 |
| Class: | Race Condition Error |
| CVE: |
CVE-2001-1066 |
| Remote: | No |
| Local: | Yes |
| Published: | Aug 27 2001 12:00AM |
| Updated: | Jul 11 2009 07:56AM |
| Credit: | This vulnerability was announced by Larry W. Cashdollar <[email protected]> on August 27, 2001 via the VulnWatch mailing list. |
| Vulnerable: |
Netscape Communicator 6.01a |
| Not Vulnerable: | |
Discussion
Netscape 6 Temp File Symbolic Link Vulnerability
Netscape 6 is a freely available web browser distributed by Netscape Communications.
Netscape 6 creates insecure temporary files when installed on Solaris systems. When installed, the program creates files in the /tmp directory using the admin prefix and process id as the file extension.
A local user that knows an administrator is installing the package could create a range of symbolic links, and potentially cause Netscape to overwrite sensitive system files, resulting in a denial of service. It is unknown whether this affects other UNIX systems.
Netscape 6 is a freely available web browser distributed by Netscape Communications.
Netscape 6 creates insecure temporary files when installed on Solaris systems. When installed, the program creates files in the /tmp directory using the admin prefix and process id as the file extension.
A local user that knows an administrator is installing the package could create a range of symbolic links, and potentially cause Netscape to overwrite sensitive system files, resulting in a denial of service. It is unknown whether this affects other UNIX systems.
Exploit / POC
Netscape 6 Temp File Symbolic Link Vulnerability
No exploit is required for this vulnerability.
No exploit is required for this vulnerability.
Solution / Fix
Netscape 6 Temp File Symbolic Link Vulnerability
Solution:
Currently the SecurityFocus staff are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution:
Currently the SecurityFocus staff are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.