FSLint Temporary File Race Condition Vulnerability
BID:4218
Info
FSLint Temporary File Race Condition Vulnerability
| Bugtraq ID: | 4218 |
| Class: | Race Condition Error |
| CVE: | |
| Remote: | No |
| Local: | Yes |
| Published: | Feb 27 2002 12:00AM |
| Updated: | Feb 27 2002 12:00AM |
| Credit: | Vulnerability discovery credited to pixelbeat <[email protected]> and ellipse <[email protected]>. |
| Vulnerable: |
FSlint FSlint 1.12 FSlint FSlint 1.11 FSlint FSlint 1.10 |
| Not Vulnerable: | |
Discussion
FSLint Temporary File Race Condition Vulnerability
FSlint is a freely available, open source program for finding various forms of lint in a file system. It is available for the Linux Operating System.
When executed, FSlint does not properly create temporary files. Between the check for existing files and symbolic links, and the creation of the temporary file, a period of time exists in which a user may be able to exploit a race condition, and launch a symbolic link attack. As FSlint is usually run by a privileged user, this could result in the removal of system files, and potential denial of service.
FSlint is a freely available, open source program for finding various forms of lint in a file system. It is available for the Linux Operating System.
When executed, FSlint does not properly create temporary files. Between the check for existing files and symbolic links, and the creation of the temporary file, a period of time exists in which a user may be able to exploit a race condition, and launch a symbolic link attack. As FSlint is usually run by a privileged user, this could result in the removal of system files, and potential denial of service.
Exploit / POC
FSLint Temporary File Race Condition Vulnerability
Currently the SecurityFocus staff are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Currently the SecurityFocus staff are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution / Fix
FSLint Temporary File Race Condition Vulnerability
Solution:
Currently the SecurityFocus staff are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution:
Currently the SecurityFocus staff are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
References
FSLint Temporary File Race Condition Vulnerability
References:
References: