CUPS '/tmp/pdf.log' Insecure Temporary File Creation Vulnerability
BID:33418
Info
CUPS '/tmp/pdf.log' Insecure Temporary File Creation Vulnerability
| Bugtraq ID: | 33418 |
| Class: | Design Error |
| CVE: |
CVE-2009-0032 |
| Remote: | No |
| Local: | Yes |
| Published: | Jan 24 2009 12:00AM |
| Updated: | Jan 26 2009 02:22PM |
| Credit: | Unknown |
| Vulnerable: |
Mandriva Linux Mandrake 2009.0 x86_64 Mandriva Linux Mandrake 2009.0 Mandriva Linux Mandrake 2008.1 x86_64 Mandriva Linux Mandrake 2008.1 Mandriva Linux Mandrake 2008.0 x86_64 Mandriva Linux Mandrake 2008.0 MandrakeSoft Multi Network Firewall 2.0 MandrakeSoft Corporate Server 4.0 x86_64 MandrakeSoft Corporate Server 3.0 x86_64 MandrakeSoft Corporate Server 3.0 MandrakeSoft Corporate Server 4.0 Easy Software Products CUPS 1.3.9 |
| Not Vulnerable: | |
Discussion
CUPS '/tmp/pdf.log' Insecure Temporary File Creation Vulnerability
CUPS creates temporary files in an insecure manner.
An attacker with local access could potentially exploit this issue to perform symbolic-link attacks, overwriting arbitrary files in the context of the affected application.
Successfully mounting a symlink attack may allow the attacker to delete or corrupt sensitive files, which may result in a denial of service. Other attacks may also be possible.
CUPS 1.3.9 is vulnerable; other versions may also be affected.
CUPS creates temporary files in an insecure manner.
An attacker with local access could potentially exploit this issue to perform symbolic-link attacks, overwriting arbitrary files in the context of the affected application.
Successfully mounting a symlink attack may allow the attacker to delete or corrupt sensitive files, which may result in a denial of service. Other attacks may also be possible.
CUPS 1.3.9 is vulnerable; other versions may also be affected.
Exploit / POC
CUPS '/tmp/pdf.log' Insecure Temporary File Creation Vulnerability
An attacker uses readily available commands to exploit this issue.
An attacker uses readily available commands to exploit this issue.
Solution / Fix
CUPS '/tmp/pdf.log' Insecure Temporary File Creation Vulnerability
Solution:
Updates are available. Please see the references for more information.
Mandriva Linux Mandrake 2009.0 x86_64
Mandriva Linux Mandrake 2009.0
Solution:
Updates are available. Please see the references for more information.
Mandriva Linux Mandrake 2009.0 x86_64
-
Mandriva cups-1.3.9-0.2mdv2009.0.x86_64.rpm
http://www.mandriva.com/en/download/ -
Mandriva cups-common-1.3.9-0.2mdv2009.0.x86_64.rpm
http://www.mandriva.com/en/download/ -
Mandriva cups-serial-1.3.9-0.2mdv2009.0.x86_64.rpm
http://www.mandriva.com/en/download/ -
Mandriva php-cups-1.3.9-0.2mdv2009.0.x86_64.rpm
http://www.mandriva.com/en/download/
Mandriva Linux Mandrake 2009.0
-
Mandriva cups-1.3.9-0.2mdv2009.0.i586.rpm
http://www.mandriva.com/en/download/ -
Mandriva cups-common-1.3.9-0.2mdv2009.0.i586.rpm
http://www.mandriva.com/en/download/ -
Mandriva cups-serial-1.3.9-0.2mdv2009.0.i586.rpm
http://www.mandriva.com/en/download/ -
Mandriva libcups2-1.3.9-0.2mdv2009.0.i586.rpm
http://www.mandriva.com/en/download/ -
Mandriva libcups2-devel-1.3.9-0.2mdv2009.0.i586.rpm
http://www.mandriva.com/en/download/ -
Mandriva php-cups-1.3.9-0.2mdv2009.0.i586.rpm
http://www.mandriva.com/en/download/
References
CUPS '/tmp/pdf.log' Insecure Temporary File Creation Vulnerability
References:
References:
- CUPS Product Page (Easy Software Products)