pyftpd Log File Insecure Temporary File Creation Vulnerability
BID:40842
Info
pyftpd Log File Insecure Temporary File Creation Vulnerability
| Bugtraq ID: | 40842 |
| Class: | Design Error |
| CVE: |
CVE-2010-2072 |
| Remote: | No |
| Local: | Yes |
| Published: | Jun 14 2010 12:00AM |
| Updated: | Apr 13 2015 09:02PM |
| Credit: | Henri Salo |
| Vulnerable: |
pyftpd pyftpd 0.8.4 pyftpd pyftpd 0.8 pyftpd pyftpd 0.6 pyftpd pyftpd 0.5 Debian Linux 5.0 sparc Debian Linux 5.0 s/390 Debian Linux 5.0 powerpc Debian Linux 5.0 mipsel Debian Linux 5.0 mips Debian Linux 5.0 m68k Debian Linux 5.0 ia-64 Debian Linux 5.0 ia-32 Debian Linux 5.0 hppa Debian Linux 5.0 armel Debian Linux 5.0 arm Debian Linux 5.0 amd64 Debian Linux 5.0 alpha Debian Linux 5.0 |
| Not Vulnerable: |
pyftpd pyftpd 0.8.5 |
Discussion
pyftpd Log File Insecure Temporary File Creation Vulnerability
pyftpd creates temporary files in an insecure manner.
An attacker with local access could potentially exploit this issue to perform symbolic-link attacks, overwriting arbitrary files in the context of the affected application.
Successfully mounting a symlink attack may allow the attacker to delete or corrupt sensitive files, which may result in a denial of service. Other attacks may also be possible.
pyftpd prior to 0.8.5 are affected.
pyftpd creates temporary files in an insecure manner.
An attacker with local access could potentially exploit this issue to perform symbolic-link attacks, overwriting arbitrary files in the context of the affected application.
Successfully mounting a symlink attack may allow the attacker to delete or corrupt sensitive files, which may result in a denial of service. Other attacks may also be possible.
pyftpd prior to 0.8.5 are affected.
Exploit / POC
pyftpd Log File Insecure Temporary File Creation Vulnerability
An attacker can use readily available commands to exploit this issue.
An attacker can use readily available commands to exploit this issue.
Solution / Fix
pyftpd Log File Insecure Temporary File Creation Vulnerability
Solution:
Updates are available. Please see the references for more details.
Solution:
Updates are available. Please see the references for more details.
References
pyftpd Log File Insecure Temporary File Creation Vulnerability
References:
References: