kbd Insecure Temporary File Creation Vulnerability
BID:47422
Info
kbd Insecure Temporary File Creation Vulnerability
| Bugtraq ID: | 47422 |
| Class: | Design Error |
| CVE: |
CVE-2011-0460 |
| Remote: | No |
| Local: | Yes |
| Published: | Apr 19 2011 12:00AM |
| Updated: | Apr 19 2011 12:00AM |
| Credit: | Reported in a SUSE Security Summary Report |
| Vulnerable: |
SuSE SUSE Linux Enterprise 11 SP1 SuSE SUSE Linux Enterprise 11 SuSE openSUSE 11.3 S.u.S.E. openSUSE 11.2 kbd kbd 0 |
| Not Vulnerable: | |
Discussion
kbd Insecure Temporary File Creation Vulnerability
kbd is prone to an insecure temporary-file-creation vulnerability.
Successfully exploiting the temporary-file-creation issue allows an attacker to overwrite arbitrary files and to perform symbolic-link attacks in the context of the affected application. Other attacks may also be possible.
kbd is prone to an insecure temporary-file-creation vulnerability.
Successfully exploiting the temporary-file-creation issue allows an attacker to overwrite arbitrary files and to perform symbolic-link attacks in the context of the affected application. Other attacks may also be possible.
Exploit / POC
kbd Insecure Temporary File Creation Vulnerability
An attacker can use readily available commands to launch attacks.
An attacker can use readily available commands to launch attacks.
Solution / Fix
kbd Insecure Temporary File Creation Vulnerability
Solution:
Updates are available. Please see the references for details.
Solution:
Updates are available. Please see the references for details.