Debian 'at-spi2-atk' CVE-2012-3378 Insecure Temporary File Handling Vulnerability
BID:55360
Info
Debian 'at-spi2-atk' CVE-2012-3378 Insecure Temporary File Handling Vulnerability
| Bugtraq ID: | 55360 |
| Class: | Design Error |
| CVE: |
CVE-2012-3378 |
| Remote: | No |
| Local: | Yes |
| Published: | Jun 18 2012 12:00AM |
| Updated: | Jun 18 2012 12:00AM |
| Credit: | Julien Cristau |
| Vulnerable: |
Debian at-spi2-atk 2.5.2-1 Debian at-spi2-atk 2.0.2-1 Debian at-spi2-atk 1.91.90 |
| Not Vulnerable: |
Debian at-spi2-atk 2.5.3 |
Discussion
Debian 'at-spi2-atk' CVE-2012-3378 Insecure Temporary File Handling Vulnerability
Debian 'at-spi2-atk' is prone to a vulnerability because it handles temporary files in an insecure manner.
Local attackers may be able to perform symbolic-link attacks to overwrite arbitrary files in the context of the affected application. Other attacks may also be possible.
at-spi2-atk versions 2.5.2-1, 2.0.2-1, and 1.91.90 are vulnerable.
Debian 'at-spi2-atk' is prone to a vulnerability because it handles temporary files in an insecure manner.
Local attackers may be able to perform symbolic-link attacks to overwrite arbitrary files in the context of the affected application. Other attacks may also be possible.
at-spi2-atk versions 2.5.2-1, 2.0.2-1, and 1.91.90 are vulnerable.
Exploit / POC
Debian 'at-spi2-atk' CVE-2012-3378 Insecure Temporary File Handling Vulnerability
An attacker can use readily available commands to exploit this issue.
An attacker can use readily available commands to exploit this issue.