Merkaartor Insecure Temporary File Creation Vulnerability
BID:36529
Info
Merkaartor Insecure Temporary File Creation Vulnerability
| Bugtraq ID: | 36529 |
| Class: | Race Condition Error |
| CVE: |
CVE-2009-4193 |
| Remote: | No |
| Local: | Yes |
| Published: | Sep 27 2009 12:00AM |
| Updated: | Apr 13 2015 09:51PM |
| Credit: | Paul Wise in a Debian bug report. |
| Vulnerable: |
Merkaartor Merkaartor 0.14 |
| Not Vulnerable: | |
Discussion
Merkaartor Insecure Temporary File Creation Vulnerability
Merkaartor creates temporary files in an insecure manner.
An attacker with local access could potentially exploit this issue to perform symbolic-link attacks to overwrite arbitrary attacker-specified files.
The issue affects Merkaartor 0.14; other versions may also be vulnerable.
Merkaartor creates temporary files in an insecure manner.
An attacker with local access could potentially exploit this issue to perform symbolic-link attacks to overwrite arbitrary attacker-specified files.
The issue affects Merkaartor 0.14; other versions may also be vulnerable.
Exploit / POC
Merkaartor Insecure Temporary File Creation Vulnerability
An attacker uses readily available commands to exploit the issue.
An attacker uses readily available commands to exploit the issue.
Solution / Fix
Merkaartor Insecure Temporary File Creation Vulnerability
Solution:
Updates are available. Please see the references for more information.
Solution:
Updates are available. Please see the references for more information.
References
Merkaartor Insecure Temporary File Creation Vulnerability
References:
References:
- #548546 - merkaartor: minor symlink attack (Debian)
- Merkaartor Homepage (Merkaartor)