XTel XTel-User Temporary File Race Condition Vulnerability
BID:3626
Info
XTel XTel-User Temporary File Race Condition Vulnerability
| Bugtraq ID: | 3626 |
| Class: | Access Validation Error |
| CVE: | |
| Remote: | No |
| Local: | Yes |
| Published: | Dec 05 2001 12:00AM |
| Updated: | Dec 05 2001 12:00AM |
| Credit: | This vulnerability was announced in a Debian Security Advisory on December 05, 2001. |
| Vulnerable: |
xtel xtel 3.2.1 xtel xtel 3.2 xtel xtel 3.1 xtel xtel 3.0 xtel xtel 2.4 xtel xtel 2.3 xtel xtel 2.2 |
| Not Vulnerable: | |
Discussion
XTel XTel-User Temporary File Race Condition Vulnerability
Xtel is a freely available, open source Linux X emulator for minitel. It is maintained by public domain.
When executed by a user, Xtel generates files in the /tmp directory with the name .xtel-$USER, where $USER represents the user executing Xtel. Xtel does not check for the existance of the .xtel-$USER file prior to execution, to ensure that it does not exist, or in a worse scenario, does not exist as a symbolic link.
Xtel is a freely available, open source Linux X emulator for minitel. It is maintained by public domain.
When executed by a user, Xtel generates files in the /tmp directory with the name .xtel-$USER, where $USER represents the user executing Xtel. Xtel does not check for the existance of the .xtel-$USER file prior to execution, to ensure that it does not exist, or in a worse scenario, does not exist as a symbolic link.
Solution / Fix
XTel XTel-User Temporary File Race Condition Vulnerability
Solution:
Vendor fixes available:
xtel xtel 3.2.1
Solution:
Vendor fixes available:
xtel xtel 3.2.1
-
Debian 2.2 alpha xtel_3.2.1-4.potato.1_alpha.deb
http://security.debian.org/dists/stable/updates/main/binary-alpha/xtel _3.2.1-4.potato.1_alpha.deb -
Debian 2.2 arm xtel_3.2.1-4.potato.1_arm.deb
http://security.debian.org/dists/stable/updates/main/binary-arm/xtel_3 .2.1-4.potato.1_arm.deb -
Debian 2.2 i386 xtel_3.2.1-4.potato.1_i386.deb
http://security.debian.org/dists/stable/updates/main/binary-i386/xtel_ 3.2.1-4.potato.1_i386.deb -
Debian 2.2 m68k xtel_3.2.1-4.potato.1_m68k.deb
http://security.debian.org/dists/stable/updates/main/binary-m68k/xtel_ 3.2.1-4.potato.1_m68k.deb -
Debian 2.2 ppc xtel_3.2.1-4.potato.1_powerpc.deb
http://security.debian.org/dists/stable/updates/main/binary-powerpc/xt el_3.2.1-4.potato.1_powerpc.deb -
Debian 2.2 sparc xtel_3.2.1-4.potato.1_sparc.deb
http://security.debian.org/dists/stable/updates/main/binary-sparc/xtel _3.2.1-4.potato.1_sparc.deb
References
XTel XTel-User Temporary File Race Condition Vulnerability
References:
References: