Fabric Insecure Temporary File Creation Vulnerability
BID:48103
Info
Fabric Insecure Temporary File Creation Vulnerability
| Bugtraq ID: | 48103 |
| Class: | Design Error |
| CVE: |
CVE-2011-2185 |
| Remote: | No |
| Local: | Yes |
| Published: | Jun 02 2011 12:00AM |
| Updated: | May 07 2015 05:07PM |
| Credit: | Steve Kemp |
| Vulnerable: |
Fabric Fabric 0.9.1 |
| Not Vulnerable: | |
Discussion
Fabric Insecure Temporary File Creation Vulnerability
Fabric is prone to a vulnerability because it creates temporary files in an insecure manner.
An attacker with local access could potentially exploit this issue to perform symbolic-link attacks, overwriting arbitrary files in the context of the affected application.
Successfully mounting a symlink attack may allow the attacker to delete or corrupt sensitive files, which may result in a denial of service. Other attacks may also be possible.
Fabric 0.9.1 is vulnerable; other versions may also be affected.
Fabric is prone to a vulnerability because it creates temporary files in an insecure manner.
An attacker with local access could potentially exploit this issue to perform symbolic-link attacks, overwriting arbitrary files in the context of the affected application.
Successfully mounting a symlink attack may allow the attacker to delete or corrupt sensitive files, which may result in a denial of service. Other attacks may also be possible.
Fabric 0.9.1 is vulnerable; other versions may also be affected.
Exploit / POC
Fabric Insecure Temporary File Creation Vulnerability
An attacker can use readily available commands to exploit this issue.
An attacker can use readily available commands to exploit this issue.
References
Fabric Insecure Temporary File Creation Vulnerability
References:
References:
- Fabric Homepage (Fabric)
- fabric is prone to file-overwrite security issue (Steve Kemp)