Geheimnis MKTemp Insecure Temporary File Vulnerability
BID:3850
Info
Geheimnis MKTemp Insecure Temporary File Vulnerability
| Bugtraq ID: | 3850 |
| Class: | Race Condition Error |
| CVE: | |
| Remote: | No |
| Local: | Yes |
| Published: | Jan 10 2002 12:00AM |
| Updated: | Jan 10 2002 12:00AM |
| Credit: | This vulnerability was announced in a Freshmeat Software Update on January 10, 2002. |
| Vulnerable: |
Geheimnis Geheimnis 1.95 |
| Not Vulnerable: |
Geheimnis Geheimnis 1.96 |
Discussion
Geheimnis MKTemp Insecure Temporary File Vulnerability
Geheimnis is a freely available, open source graphical application. It is designed to act as a frontend to GnuPG or PGP, and is usually used on the Linux or Unix platforms with KDE2.
Geheimnis uses the mktemp function to generate temporary files. mktemp requires a filename ending with an extension of XXXXXX (six x's). When the temporary file is generated, the name of the file is generated by taking the predetermined name in the program, and filling the field of X's with a random value. However, some operating systems fill the first five X's in the field with the process number, and the last X with one of twenty-six lower case letters in the alphabet. This could lead to a symbolic link attack in the event that the file name is guessed, and the existence of a file using the same name is not checked for by Geheimnis.
Geheimnis is a freely available, open source graphical application. It is designed to act as a frontend to GnuPG or PGP, and is usually used on the Linux or Unix platforms with KDE2.
Geheimnis uses the mktemp function to generate temporary files. mktemp requires a filename ending with an extension of XXXXXX (six x's). When the temporary file is generated, the name of the file is generated by taking the predetermined name in the program, and filling the field of X's with a random value. However, some operating systems fill the first five X's in the field with the process number, and the last X with one of twenty-six lower case letters in the alphabet. This could lead to a symbolic link attack in the event that the file name is guessed, and the existence of a file using the same name is not checked for by Geheimnis.
Exploit / POC
Geheimnis MKTemp Insecure Temporary File Vulnerability
Currently the SecurityFocus staff are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Currently the SecurityFocus staff are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution / Fix
Geheimnis MKTemp Insecure Temporary File Vulnerability
Solution:
Fixed version available:
Geheimnis Geheimnis 1.95
Solution:
Fixed version available:
Geheimnis Geheimnis 1.95
-
Geheimnis Geheimnis 1.96
http://prdownloads.sourceforge.net/geheimnis/geheimnis-1.96.tar.gz