Nautilus Local File Corruption Vulnerability
BID:4373
Info
Nautilus Local File Corruption Vulnerability
| Bugtraq ID: | 4373 |
| Class: | Access Validation Error |
| CVE: | |
| Remote: | No |
| Local: | Yes |
| Published: | Mar 27 2002 12:00AM |
| Updated: | Mar 27 2002 12:00AM |
| Credit: | Joe Testa <[email protected]> |
| Vulnerable: |
Eazel Nautilus 1.0.4 |
| Not Vulnerable: | |
Discussion
Nautilus Local File Corruption Vulnerability
When copying files from one directory to another, Nautilus creates a small XML file with the filename '.nautilus-metafile.xml' in the target directory. When writing this file, there are no checks to ensure that it does not already exist. Symbolic links will also be followed.
Local attackers may exploit this behaviour to overwrite files belonging to other users if they can create a symbolic link in the target directory.
When copying files from one directory to another, Nautilus creates a small XML file with the filename '.nautilus-metafile.xml' in the target directory. When writing this file, there are no checks to ensure that it does not already exist. Symbolic links will also be followed.
Local attackers may exploit this behaviour to overwrite files belonging to other users if they can create a symbolic link in the target directory.
Exploit / POC
Nautilus Local File Corruption Vulnerability
No exploit code is required.
No exploit code is required.
Solution / Fix
Nautilus Local File Corruption Vulnerability
Solution:
RedHat and Slackware both have upgrades/patches to rectify the problem. It is advisable to update your system to the new version of Nautilus.
Patches for Slackware are reportedly available at the following address. ftp://ftp.slackware.com/pub/slackware/slackware-8.0/patches/
However, SecurityFocus has not been able to verify the existence of the patches.
Eazel Nautilus 1.0.4
Solution:
RedHat and Slackware both have upgrades/patches to rectify the problem. It is advisable to update your system to the new version of Nautilus.
Patches for Slackware are reportedly available at the following address. ftp://ftp.slackware.com/pub/slackware/slackware-8.0/patches/
However, SecurityFocus has not been able to verify the existence of the patches.
Eazel Nautilus 1.0.4
-
Red Hat nautilus-1.0.4-46.i386.rpm
ftp://updates.redhat.com/7.2/en/os/i386/nautilus-1.0.4-46.i386.rpm -
Red Hat nautilus-1.0.4-46.ia64.rpm
ftp://updates.redhat.com/7.2/en/os/ia64/nautilus-1.0.4-46.ia64.rpm -
Red Hat nautilus-devel-1.0.4-46.i386.rpm
ftp://updates.redhat.com/7.2/en/os/i386/nautilus-devel-1.0.4-46.i386.r pm -
Red Hat nautilus-devel-1.0.4-46.ia64.rpm
ftp://updates.redhat.com/7.2/en/os/ia64/nautilus-devel-1.0.4-46.ia64.r pm -
Red Hat nautilus-mozilla-1.0.4-46.i386.rpm
ftp://updates.redhat.com/7.2/en/os/i386/nautilus-mozilla-1.0.4-46.i386 .rpm
References
Nautilus Local File Corruption Vulnerability
References:
References: