KDE2 KDEUtils KLPRFax_Filter Insecure Temporary File Creation Vulnerability
BID:3694
Info
KDE2 KDEUtils KLPRFax_Filter Insecure Temporary File Creation Vulnerability
| Bugtraq ID: | 3694 |
| Class: | Access Validation Error |
| CVE: |
CVE-2001-1197 |
| Remote: | No |
| Local: | Yes |
| Published: | Dec 14 2001 12:00AM |
| Updated: | Jul 11 2009 09:06AM |
| Credit: | This vulnerability was announced by wang yuan <[email protected]> via Bugtraq on December 14, 2001. |
| Vulnerable: |
KDE KDEUtils 2.2 -2 KDE KDEUtils 2.2 |
| Not Vulnerable: | |
Discussion
KDE2 KDEUtils KLPRFax_Filter Insecure Temporary File Creation Vulnerability
KDE2 is a freely available, open source X Window System manager. It is maintained by the KDE Project.
klprfax_filter is a program included with KDE2 for fax functionality. A problem exists in the creation of files in the temporary directory. The program does not check for the existance of the klprfax.filter file prior to attempting to send input to it. This makes it possible for a local user to create a symbolic link to any file that is write-accessible by the user executing klprfax_filter, and overwrite the contents of the file.
KDE2 is a freely available, open source X Window System manager. It is maintained by the KDE Project.
klprfax_filter is a program included with KDE2 for fax functionality. A problem exists in the creation of files in the temporary directory. The program does not check for the existance of the klprfax.filter file prior to attempting to send input to it. This makes it possible for a local user to create a symbolic link to any file that is write-accessible by the user executing klprfax_filter, and overwrite the contents of the file.
Exploit / POC
KDE2 KDEUtils KLPRFax_Filter Insecure Temporary File Creation Vulnerability
No exploit is required for this vulnerability.
No exploit is required for this vulnerability.
Solution / Fix
KDE2 KDEUtils KLPRFax_Filter Insecure Temporary File Creation Vulnerability
Solution:
Currently the SecurityFocus staff are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution:
Currently the SecurityFocus staff are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
References
KDE2 KDEUtils KLPRFax_Filter Insecure Temporary File Creation Vulnerability
References:
References: