Debian and Ubuntu foo2zjs Insecure Temporary File Creation Vulnerability
BID:48586
Info
Debian and Ubuntu foo2zjs Insecure Temporary File Creation Vulnerability
| Bugtraq ID: | 48586 |
| Class: | Design Error |
| CVE: | |
| Remote: | No |
| Local: | Yes |
| Published: | Jul 06 2011 12:00AM |
| Updated: | Jul 06 2011 12:00AM |
| Credit: | daveb |
| Vulnerable: |
Ubuntu foo2zjs 0 Debian foo2zjs 0 |
| Not Vulnerable: | |
Discussion
Debian and Ubuntu foo2zjs Insecure Temporary File Creation Vulnerability
foo2zjs on Debian and Ubuntu creates temporary files in an insecure manner.
An attacker with local access could potentially exploit this issue to perform symbolic-link attacks, overwriting arbitrary files in the context of the affected application.
Successfully mounting a symlink attack may allow the attacker to delete or corrupt sensitive files, which may result in a denial of service. Other attacks may also be possible.
foo2zjs on Debian and Ubuntu creates temporary files in an insecure manner.
An attacker with local access could potentially exploit this issue to perform symbolic-link attacks, overwriting arbitrary files in the context of the affected application.
Successfully mounting a symlink attack may allow the attacker to delete or corrupt sensitive files, which may result in a denial of service. Other attacks may also be possible.
Exploit / POC
Debian and Ubuntu foo2zjs Insecure Temporary File Creation Vulnerability
An attacker can use readily available commands to exploit this issue.
An attacker can use readily available commands to exploit this issue.
Solution / Fix
Debian and Ubuntu foo2zjs Insecure Temporary File Creation Vulnerability
Solution:
Currently we are not aware of any vendor-supplied patches. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Solution:
Currently we are not aware of any vendor-supplied patches. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
References
Debian and Ubuntu foo2zjs Insecure Temporary File Creation Vulnerability
References:
References:
- Bug #805370 /usr/bin/getweb is vulnerable to "Insecure temporary file creation" (daveb)
- CVE Request: foo2zjs (Marc Deslauriers)
- Debian Homepage (Debian)
- Ubuntu Homepage (Ubuntu)