Ghostscript Insecure Temporary File Creation Vulnerability
BID:40426
Info
Ghostscript Insecure Temporary File Creation Vulnerability
| Bugtraq ID: | 40426 |
| Class: | Design Error |
| CVE: |
CVE-2010-2056 |
| Remote: | No |
| Local: | Yes |
| Published: | May 28 2010 12:00AM |
| Updated: | Apr 13 2015 09:37PM |
| Credit: | Paul Szabo |
| Vulnerable: |
Mandriva Linux Mandrake 2010.1 x86_64 Mandriva Linux Mandrake 2010.1 Mandriva Linux Mandrake 2010.0 x86_64 Mandriva Linux Mandrake 2010.0 MandrakeSoft Enterprise Server 5 x86_64 MandrakeSoft Enterprise Server 5 MandrakeSoft Corporate Server 4.0 x86_64 MandrakeSoft Corporate Server 4.0 Ghostscript Ghostscript 8.15.2 Ghostscript Ghostscript 8.0.1 Ghostscript Ghostscript 5.50 Ghostscript Ghostscript 8.64 Ghostscript Ghostscript 8.61 Ghostscript Ghostscript 8.60 Ghostscript Ghostscript 8.57 Ghostscript Ghostscript 8.56 Ghostscript Ghostscript 8.54 Ghostscript Ghostscript 8.15 Ghostscript Ghostscript 7.07 Ghostscript Ghostscript 7.05 Ghostscript Ghostscript 0 Gentoo Linux |
| Not Vulnerable: | |
Discussion
Ghostscript Insecure Temporary File Creation Vulnerability
Ghostscript creates temporary files in an insecure manner.
An attacker with local access could potentially exploit this issue to perform symbolic-link attacks, overwriting arbitrary files in the context of the affected application.
Successfully mounting a symlink attack may allow the attacker to delete or corrupt sensitive files, which may result in a denial of service. Other attacks may also be possible.
Ghostscript 8.64 is vulnerable; other versions may also be affected.
Ghostscript creates temporary files in an insecure manner.
An attacker with local access could potentially exploit this issue to perform symbolic-link attacks, overwriting arbitrary files in the context of the affected application.
Successfully mounting a symlink attack may allow the attacker to delete or corrupt sensitive files, which may result in a denial of service. Other attacks may also be possible.
Ghostscript 8.64 is vulnerable; other versions may also be affected.
Exploit / POC
Ghostscript Insecure Temporary File Creation Vulnerability
An attacker uses readily available commands to exploit this issue.
An attacker uses readily available commands to exploit this issue.
Solution / Fix
Ghostscript Insecure Temporary File Creation Vulnerability
Solution:
Updates are available. Please see the references for more information.
Mandriva Linux Mandrake 2010.0 x86_64
Mandriva Linux Mandrake 2010.1
MandrakeSoft Enterprise Server 5 x86_64
MandrakeSoft Corporate Server 4.0
MandrakeSoft Enterprise Server 5
Mandriva Linux Mandrake 2010.1 x86_64
Mandriva Linux Mandrake 2010.0
MandrakeSoft Corporate Server 4.0 x86_64
Solution:
Updates are available. Please see the references for more information.
Mandriva Linux Mandrake 2010.0 x86_64
-
Mandriva gv-3.7.1-0.1mdv2010.0.x86_64.rpm
http://www.mandriva.com/en/download/
Mandriva Linux Mandrake 2010.1
-
Mandriva gv-3.7.1-0.1mdv2010.1.i586.rpm
http://www.mandriva.com/en/download/
MandrakeSoft Enterprise Server 5 x86_64
-
Mandriva gv-3.7.1-0.1mdvmes5.1.x86_64.rpm
http://www.mandriva.com/en/download/
MandrakeSoft Corporate Server 4.0
-
Mandriva gv-3.7.1-0.1.20060mlcs4.i586.rpm
http://www.mandriva.com/en/download/
MandrakeSoft Enterprise Server 5
-
Mandriva gv-3.7.1-0.1mdvmes5.1.i586.rpm
http://www.mandriva.com/en/download/
Mandriva Linux Mandrake 2010.1 x86_64
-
Mandriva gv-3.7.1-0.1mdv2010.1.x86_64.rpm
http://www.mandriva.com/en/download/
Mandriva Linux Mandrake 2010.0
-
Mandriva gv-3.7.1-0.1mdv2010.0.i586.rpm
http://www.mandriva.com/en/download/
MandrakeSoft Corporate Server 4.0 x86_64
-
Mandriva gv-3.7.1-0.1.20060mlcs4.x86_64.rpm
http://www.mandriva.com/en/download/
References
Ghostscript Insecure Temporary File Creation Vulnerability
References:
References: