Ubuntu Update Manager Insecure Temporary Directory Creation Vulnerability
BID:50832
Info
Ubuntu Update Manager Insecure Temporary Directory Creation Vulnerability
| Bugtraq ID: | 50832 |
| Class: | Design Error |
| CVE: |
CVE-2011-3154 |
| Remote: | No |
| Local: | Yes |
| Published: | Nov 28 2011 12:00AM |
| Updated: | Nov 28 2011 12:00AM |
| Credit: | David Black |
| Vulnerable: |
Ubuntu Ubuntu Linux 8.04 LTS sparc Ubuntu Ubuntu Linux 8.04 LTS powerpc Ubuntu Ubuntu Linux 8.04 LTS lpia Ubuntu Ubuntu Linux 8.04 LTS i386 Ubuntu Ubuntu Linux 8.04 LTS amd64 Ubuntu Ubuntu Linux 11.10 i386 Ubuntu Ubuntu Linux 11.10 amd64 Ubuntu Ubuntu Linux 11.04 powerpc Ubuntu Ubuntu Linux 11.04 i386 Ubuntu Ubuntu Linux 11.04 ARM Ubuntu Ubuntu Linux 11.04 amd64 Ubuntu Ubuntu Linux 10.10 powerpc Ubuntu Ubuntu Linux 10.10 i386 Ubuntu Ubuntu Linux 10.10 ARM Ubuntu Ubuntu Linux 10.10 amd64 Ubuntu Ubuntu Linux 10.04 sparc Ubuntu Ubuntu Linux 10.04 powerpc Ubuntu Ubuntu Linux 10.04 i386 Ubuntu Ubuntu Linux 10.04 ARM Ubuntu Ubuntu Linux 10.04 amd64 |
| Not Vulnerable: | |
Discussion
Ubuntu Update Manager Insecure Temporary Directory Creation Vulnerability
Ubuntu Update Manager is prone to a security vulnerability because of an insecure temporary directory creation.
A local attacker can exploit this issue to read certain sensitive files contained in an affected directory. This may lead to further attacks.
Ubuntu Update Manager is prone to a security vulnerability because of an insecure temporary directory creation.
A local attacker can exploit this issue to read certain sensitive files contained in an affected directory. This may lead to further attacks.
Exploit / POC
Ubuntu Update Manager Insecure Temporary Directory Creation Vulnerability
Attackers need local interactive access to exploit this issue.
Attackers need local interactive access to exploit this issue.
Solution / Fix
Ubuntu Update Manager Insecure Temporary Directory Creation Vulnerability
Solution:
Updates are available. Please see the references for more information.
Solution:
Updates are available. Please see the references for more information.
References
Ubuntu Update Manager Insecure Temporary Directory Creation Vulnerability
References:
References:
- Ubuntu Homepage (Ubuntu)