openCryptoki Multiple Insecure File Creation Vulnerabilities
BID:55627
Info
openCryptoki Multiple Insecure File Creation Vulnerabilities
| Bugtraq ID: | 55627 |
| Class: | Design Error |
| CVE: |
CVE-2012-4454 CVE-2012-4455 |
| Remote: | No |
| Local: | Yes |
| Published: | Sep 20 2012 12:00AM |
| Updated: | Sep 28 2012 03:10PM |
| Credit: | Niels Heinen |
| Vulnerable: | |
| Not Vulnerable: | |
Discussion
openCryptoki Multiple Insecure File Creation Vulnerabilities
openCryptoki is prone to multiple vulnerabilities because it creates certain files in an insecure manner.
An attacker with local access could potentially exploit these issues to perform symbolic-link attacks with root privileges.
Successfully mounting a symlink attack may allow the attacker to corrupt sensitive files in the context of root user. Other attacks may also be possible.
openCryptoki is prone to multiple vulnerabilities because it creates certain files in an insecure manner.
An attacker with local access could potentially exploit these issues to perform symbolic-link attacks with root privileges.
Successfully mounting a symlink attack may allow the attacker to corrupt sensitive files in the context of root user. Other attacks may also be possible.
Exploit / POC
openCryptoki Multiple Insecure File Creation Vulnerabilities
An attacker can use readily available commands to exploit this issue.
An attacker can use readily available commands to exploit this issue.
Solution / Fix
openCryptoki Multiple Insecure File Creation Vulnerabilities
Solution:
Currently we are not aware of any vendor-supplied patches. If you feel we are in error or are aware of more recent information, please mail us at: [email protected].
Solution:
Currently we are not aware of any vendor-supplied patches. If you feel we are in error or are aware of more recent information, please mail us at: [email protected].
References
openCryptoki Multiple Insecure File Creation Vulnerabilities
References:
References: