Ubuntu 'xdiagnose' Package CVE-2012-5355 Insecure Temporary File Creation Vulnerability
BID:55912
Info
Ubuntu 'xdiagnose' Package CVE-2012-5355 Insecure Temporary File Creation Vulnerability
| Bugtraq ID: | 55912 |
| Class: | Design Error |
| CVE: |
CVE-2012-5355 |
| Remote: | No |
| Local: | Yes |
| Published: | Oct 02 2012 12:00AM |
| Updated: | Oct 02 2012 12:00AM |
| Credit: | Alec Warner |
| Vulnerable: |
Ubuntu xdiagnose 2.5.2 Ubuntu Ubuntu Linux 12.04 LTS i386 Ubuntu Ubuntu Linux 12.04 LTS amd64 |
| Not Vulnerable: |
Ubuntu xdiagnose 2.5.2ubuntu0.1 |
Discussion
Ubuntu 'xdiagnose' Package CVE-2012-5355 Insecure Temporary File Creation Vulnerability
Ubuntu 'xdiagnose' package is prone to an insecure temporary file-creation vulnerability.
An attacker with local access could potentially exploit this issue to perform symbolic-link attacks overwriting arbitrary files in the context of the affected application.
Successfully mounting a symlink attack may allow the attacker to delete or corrupt sensitive files, which can result in denial of service. Other attacks may also be possible.
Versions prior to xdiagnose 2.5.2ubuntu0.1 are vulnerable.
Ubuntu 'xdiagnose' package is prone to an insecure temporary file-creation vulnerability.
An attacker with local access could potentially exploit this issue to perform symbolic-link attacks overwriting arbitrary files in the context of the affected application.
Successfully mounting a symlink attack may allow the attacker to delete or corrupt sensitive files, which can result in denial of service. Other attacks may also be possible.
Versions prior to xdiagnose 2.5.2ubuntu0.1 are vulnerable.
Solution / Fix
Ubuntu 'xdiagnose' Package CVE-2012-5355 Insecure Temporary File Creation Vulnerability
Solution:
Updates are available. Please see the reference for more details.
Solution:
Updates are available. Please see the reference for more details.