xNBD '/tmp/xnbd.log' Insecure Temporary File Handling Vulnerability
BID:57784
Info
xNBD '/tmp/xnbd.log' Insecure Temporary File Handling Vulnerability
| Bugtraq ID: | 57784 |
| Class: | Design Error |
| CVE: |
CVE-2013-0265 |
| Remote: | No |
| Local: | Yes |
| Published: | Feb 06 2013 12:00AM |
| Updated: | Feb 14 2013 12:21PM |
| Credit: | Sebastian Pipping |
| Vulnerable: | |
| Not Vulnerable: | |
Discussion
xNBD '/tmp/xnbd.log' Insecure Temporary File Handling Vulnerability
xNBD is prone to a vulnerability because it handles temporary files in an insecure manner.
Local attackers may leverage this issue to perform symbolic-link attacks in the context of the affected application. Other attacks may also be possible.
xNBD is prone to a vulnerability because it handles temporary files in an insecure manner.
Local attackers may leverage this issue to perform symbolic-link attacks in the context of the affected application. Other attacks may also be possible.
Exploit / POC
xNBD '/tmp/xnbd.log' Insecure Temporary File Handling Vulnerability
An attacker can use readily available commands to exploit this issue.
The following exploit code is available:
An attacker can use readily available commands to exploit this issue.
The following exploit code is available:
Solution / Fix
xNBD '/tmp/xnbd.log' Insecure Temporary File Handling Vulnerability
Solution:
Updates are available. Please see the references for more information.
Solution:
Updates are available. Please see the references for more information.
References
xNBD '/tmp/xnbd.log' Insecure Temporary File Handling Vulnerability
References:
References: