RPCBind Multiple Insecure Temporary File Creation Vulnerabilities
BID:40562
Info
RPCBind Multiple Insecure Temporary File Creation Vulnerabilities
| Bugtraq ID: | 40562 |
| Class: | Race Condition Error |
| CVE: | |
| Remote: | No |
| Local: | Yes |
| Published: | Jun 03 2010 12:00AM |
| Updated: | Jun 03 2010 12:00AM |
| Credit: | Guillem Jover |
| Vulnerable: |
RPCBind RPCBind 0.2 Red Hat Fedora 13 Red Hat Fedora 12 Red Hat Fedora 11 Debian Linux 5.0 sparc Debian Linux 5.0 s/390 Debian Linux 5.0 powerpc Debian Linux 5.0 mipsel Debian Linux 5.0 mips Debian Linux 5.0 m68k Debian Linux 5.0 ia-64 Debian Linux 5.0 ia-32 Debian Linux 5.0 hppa Debian Linux 5.0 armel Debian Linux 5.0 arm Debian Linux 5.0 amd64 Debian Linux 5.0 alpha Debian Linux 5.0 |
| Not Vulnerable: | |
Discussion
RPCBind Multiple Insecure Temporary File Creation Vulnerabilities
The RPCBind daemon creates temporary files in an insecure manner.
An attacker with local access could potentially exploit these issues to perform symbolic link attacks to overwrite arbitrary attacker-specified files. This could facilitate a complete compromise of the affected computer.
The RPCBind daemon creates temporary files in an insecure manner.
An attacker with local access could potentially exploit these issues to perform symbolic link attacks to overwrite arbitrary attacker-specified files. This could facilitate a complete compromise of the affected computer.
Exploit / POC
RPCBind Multiple Insecure Temporary File Creation Vulnerabilities
A local attacker can use readily available commands to exploit these issues.
A local attacker can use readily available commands to exploit these issues.
Solution / Fix
RPCBind Multiple Insecure Temporary File Creation Vulnerabilities
Solution:
Currently we are not aware of any vendor-supplied patches. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Solution:
Currently we are not aware of any vendor-supplied patches. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
References
RPCBind Multiple Insecure Temporary File Creation Vulnerabilities
References:
References:
- Bug 599697 - rpcbind: Insecure (predictable) temporary file use (Jan Lieskovsky)
- #583435 rpcbind: Insecure handling of state files (Guillem Jover)
- RPCBind Homepage (RPCBind)