Cisco Tac_Plus Accounting Directive Insecure File Creation Vulnerability
BID:4003
Info
Cisco Tac_Plus Accounting Directive Insecure File Creation Vulnerability
| Bugtraq ID: | 4003 |
| Class: | Access Validation Error |
| CVE: |
CVE-2002-0225 |
| Remote: | No |
| Local: | Yes |
| Published: | Jan 31 2002 12:00AM |
| Updated: | Jul 11 2009 09:56AM |
| Credit: | This vulnerability was announced by Kevin A. Nassery <[email protected]> via Bugtraq on January 30, 2002. |
| Vulnerable: |
Cisco tac_plus F4.0.4 alpha |
| Not Vulnerable: |
Devrim Seral TACACS+ v9 Devrim Seral TACACS+ v8 |
Discussion
Cisco Tac_Plus Accounting Directive Insecure File Creation Vulnerability
tac_plus is an open source, freely available implementation of a TACACS+ server. It was originally written by Cisco.
tac_plus creates accounting files insecurely. When tac_plus is started, it creates the file specified in the "account file =" configuration parameter with world-writable permissions. This could allow a local user to alter the contents, or entirely remove the accounting file.
tac_plus is an open source, freely available implementation of a TACACS+ server. It was originally written by Cisco.
tac_plus creates accounting files insecurely. When tac_plus is started, it creates the file specified in the "account file =" configuration parameter with world-writable permissions. This could allow a local user to alter the contents, or entirely remove the accounting file.
Exploit / POC
Cisco Tac_Plus Accounting Directive Insecure File Creation Vulnerability
No exploit is required to take advantage of this vulnerability.
No exploit is required to take advantage of this vulnerability.
Solution / Fix
Cisco Tac_Plus Accounting Directive Insecure File Creation Vulnerability
Solution:
Currently the SecurityFocus staff are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution:
Currently the SecurityFocus staff are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
References
Cisco Tac_Plus Accounting Directive Insecure File Creation Vulnerability
References:
References: