SUSE Linux 'scsi_discovery tool' Insecure Temporary File Creation Vulnerability
BID:36887
Info
SUSE Linux 'scsi_discovery tool' Insecure Temporary File Creation Vulnerability
| Bugtraq ID: | 36887 |
| Class: | Race Condition Error |
| CVE: |
CVE-2009-1297 |
| Remote: | No |
| Local: | Yes |
| Published: | Oct 30 2009 12:00AM |
| Updated: | Apr 10 2013 02:58PM |
| Credit: | Reported in a SUSE Linux security advisory |
| Vulnerable: |
Ubuntu Ubuntu Linux 8.04 LTS sparc Ubuntu Ubuntu Linux 8.04 LTS powerpc Ubuntu Ubuntu Linux 8.04 LTS lpia Ubuntu Ubuntu Linux 8.04 LTS i386 Ubuntu Ubuntu Linux 8.04 LTS amd64 SuSE SUSE Linux Enterprise SDK 10 SP2 SuSE SUSE Linux Enterprise 11 SuSE openSUSE 10.3 S.u.S.E. openSUSE 11.1 S.u.S.E. openSUSE 11.0 |
| Not Vulnerable: | |
Discussion
SUSE Linux 'scsi_discovery tool' Insecure Temporary File Creation Vulnerability
SUSE Linux creates temporary files in an insecure manner.
An attacker with local access could potentially exploit this issue to perform symbolic-link attacks to overwrite arbitrary attacker-specified files.
The following versions are affected:
openSUSE 10.3 through 11.1
SUSE Linux Enterprise (SLE) 10 SP2 and 11
SUSE Linux creates temporary files in an insecure manner.
An attacker with local access could potentially exploit this issue to perform symbolic-link attacks to overwrite arbitrary attacker-specified files.
The following versions are affected:
openSUSE 10.3 through 11.1
SUSE Linux Enterprise (SLE) 10 SP2 and 11
Exploit / POC
SUSE Linux 'scsi_discovery tool' Insecure Temporary File Creation Vulnerability
An attacker uses readily available commands to exploit the issue.
An attacker uses readily available commands to exploit the issue.
Solution / Fix
SUSE Linux 'scsi_discovery tool' Insecure Temporary File Creation Vulnerability
Solution:
Updates are available. Please see the references for more information.
Solution:
Updates are available. Please see the references for more information.
References
SUSE Linux 'scsi_discovery tool' Insecure Temporary File Creation Vulnerability
References:
References:
- openSUSE Homepage (SUSE)