Gri Insecure Temporary File Creation Vulnerability
BID:46664
Info
Gri Insecure Temporary File Creation Vulnerability
| Bugtraq ID: | 46664 |
| Class: | Design Error |
| CVE: | |
| Remote: | No |
| Local: | Yes |
| Published: | Mar 03 2011 12:00AM |
| Updated: | Mar 03 2011 12:00AM |
| Credit: | Henri Salo |
| Vulnerable: |
Gri Gri 2.12.17 Gri Gri 2.12.13 |
| Not Vulnerable: |
Gri Gri 2.12.22 Gri Gri 2.12.21 |
Discussion
Gri Insecure Temporary File Creation Vulnerability
Gri is prone to an insecure temporary-file-creation vulnerability.
Successfully exploiting the temporary-file-creation issue allows an attacker to overwrite arbitrary files and to perform symbolic-link attacks in the context of the affected application. Other attacks may also be possible.
Gri versions 2.12.13 and 2.12.17 are vulnerable.
Gri is prone to an insecure temporary-file-creation vulnerability.
Successfully exploiting the temporary-file-creation issue allows an attacker to overwrite arbitrary files and to perform symbolic-link attacks in the context of the affected application. Other attacks may also be possible.
Gri versions 2.12.13 and 2.12.17 are vulnerable.
Exploit / POC
Gri Insecure Temporary File Creation Vulnerability
An attacker can use readily available commands to launch attacks.
An attacker can use readily available commands to launch attacks.
Solution / Fix
Gri Insecure Temporary File Creation Vulnerability
Solution:
Vendor updates are available. Please see the references for more information.
Solution:
Vendor updates are available. Please see the references for more information.
References
Gri Insecure Temporary File Creation Vulnerability
References:
References:
- Gri Homepage (Gri)
- Gri Security Update (Gri)
- Debian Security Advisory (Debian Security)