ISC DHCP 'dhcpd -t' Command Insecure Temporary File Creation Vulnerability
BID:35670
Info
ISC DHCP 'dhcpd -t' Command Insecure Temporary File Creation Vulnerability
| Bugtraq ID: | 35670 |
| Class: | Race Condition Error |
| CVE: |
CVE-2009-1893 |
| Remote: | No |
| Local: | Yes |
| Published: | Jul 14 2009 12:00AM |
| Updated: | Jan 08 2010 06:51PM |
| Credit: | Tomas Hoger |
| Vulnerable: |
VMWare VirtualCenter 2.0.2 VMWare VirtualCenter 2.5 VMWare vCenter 4.0 VMWare ESXi Server 4.0 VMWare ESX Server 3.0.3 VMWare ESX Server 4.0 VMWare ESX Server 3.5 Redhat Enterprise Linux WS 3 Redhat Enterprise Linux ES 3 Redhat Enterprise Linux AS 3 Redhat Desktop 3.0 ISC DHCPD 3.1.1 ISC DHCPD 3.0.4 ISC DHCPD 3.0.1 rc9 ISC DHCPD 3.0.1 rc8 ISC DHCPD 3.0.1 rc7 ISC DHCPD 3.0.1 rc6 ISC DHCPD 3.0.1 rc5 ISC DHCPD 3.0.1 rc4 ISC DHCPD 3.0.1 rc3 ISC DHCPD 3.0.1 rc2 ISC DHCPD 3.0.1 rc14 ISC DHCPD 3.0.1 rc13 ISC DHCPD 3.0.1 rc12 ISC DHCPD 3.0.1 rc11 ISC DHCPD 3.0.1 rc10 ISC DHCPD 3.0.1 rc1 ISC DHCPD 3.0 rc4 ISC DHCPD 3.0 rc12 ISC DHCPD 3.0 pl2 ISC DHCPD 3.0 pl1 ISC DHCPD 3.0 ISC DHCPD 3.0.5b1 ISC DHCPD 3.0.2rc1 ISC DHCPD 2.0.pl5 ISC DHCPD 2.0 Admanager Admanager 3.0 pl2 |
| Not Vulnerable: | |
Discussion
ISC DHCP 'dhcpd -t' Command Insecure Temporary File Creation Vulnerability
ISC DHCP creates temporary files in an insecure manner.
An attacker with local access could potentially exploit this issue to perform symbolic link attacks to overwrite arbitrary attacker-specified files.
ISC DHCP creates temporary files in an insecure manner.
An attacker with local access could potentially exploit this issue to perform symbolic link attacks to overwrite arbitrary attacker-specified files.
Exploit / POC
ISC DHCP 'dhcpd -t' Command Insecure Temporary File Creation Vulnerability
An attacker can use readily available commands to exploit the issue.
An attacker can use readily available commands to exploit the issue.
Solution / Fix
ISC DHCP 'dhcpd -t' Command Insecure Temporary File Creation Vulnerability
Solution:
The vendor has released an update. Please see the references for details.
Solution:
The vendor has released an update. Please see the references for details.
References
ISC DHCP 'dhcpd -t' Command Insecure Temporary File Creation Vulnerability
References:
References: