crypto-utils 'genkey' Script CVE-2012-3504 Insecure Temporary File Handling Vulnerability
BID:55756
Info
crypto-utils 'genkey' Script CVE-2012-3504 Insecure Temporary File Handling Vulnerability
| Bugtraq ID: | 55756 |
| Class: | Design Error |
| CVE: |
CVE-2012-3504 |
| Remote: | No |
| Local: | Yes |
| Published: | Oct 02 2012 12:00AM |
| Updated: | Apr 13 2015 09:37PM |
| Credit: | Joe Orton |
| Vulnerable: |
Redhat Enterprise Linux 6 Redhat crypto-utils 0 |
| Not Vulnerable: | |
Discussion
crypto-utils 'genkey' Script CVE-2012-3504 Insecure Temporary File Handling Vulnerability
crypto-utils is prone to a vulnerability regarding the handling of temporary files.
Successful exploits may allow attackers to mount a symlink attack, which may allow the attacker to overwrite or corrupt sensitive files. This may result in a denial-of-service condition. Other attacks may also be possible.
crypto-utils is prone to a vulnerability regarding the handling of temporary files.
Successful exploits may allow attackers to mount a symlink attack, which may allow the attacker to overwrite or corrupt sensitive files. This may result in a denial-of-service condition. Other attacks may also be possible.
Exploit / POC
crypto-utils 'genkey' Script CVE-2012-3504 Insecure Temporary File Handling Vulnerability
An attacker can use readily available commands to launch attacks.
An attacker can use readily available commands to launch attacks.