Oracle Solaris 'flar' Insecure Temporary File Creation Vulnerability
BID:41619
Info
Oracle Solaris 'flar' Insecure Temporary File Creation Vulnerability
| Bugtraq ID: | 41619 |
| Class: | Design Error |
| CVE: |
CVE-2010-2382 |
| Remote: | No |
| Local: | Yes |
| Published: | Jul 12 2010 12:00AM |
| Updated: | Jan 05 2011 08:52PM |
| Credit: | Frank Stuart |
| Vulnerable: |
Sun Solaris 9_x86 Sun Solaris 9_sparc Sun Solaris 8_x86 Sun Solaris 8_sparc Sun Solaris 10_x86 Sun Solaris 10_sparc |
| Not Vulnerable: | |
Discussion
Oracle Solaris 'flar' Insecure Temporary File Creation Vulnerability
Oracle Solaris is prone to an insecure temporary file creation vulnerability.
A local attacker can exploit this issue to overwrite arbitrary files with the privileges of the affected process. This will likely result in denial-of-service conditions, other attacks may also be possible.
Oracle Solaris 8, 9 and 10 are vulnerable.
Oracle Solaris is prone to an insecure temporary file creation vulnerability.
A local attacker can exploit this issue to overwrite arbitrary files with the privileges of the affected process. This will likely result in denial-of-service conditions, other attacks may also be possible.
Oracle Solaris 8, 9 and 10 are vulnerable.
Exploit / POC
Oracle Solaris 'flar' Insecure Temporary File Creation Vulnerability
The following exploit code is available:
The following exploit code is available:
Solution / Fix
Oracle Solaris 'flar' Insecure Temporary File Creation Vulnerability
Solution:
Vendor updates are available. Please contact the vendor for more information.
Solution:
Vendor updates are available. Please contact the vendor for more information.
References
Oracle Solaris 'flar' Insecure Temporary File Creation Vulnerability
References:
References: