Apache Commons FileUpload CVE-2013-0248 Insecure Temporary File Creation Vulnerability
BID:58326
Info
Apache Commons FileUpload CVE-2013-0248 Insecure Temporary File Creation Vulnerability
| Bugtraq ID: | 58326 |
| Class: | Input Validation Error |
| CVE: |
CVE-2013-0248 |
| Remote: | No |
| Local: | Yes |
| Published: | Mar 06 2013 12:00AM |
| Updated: | Nov 03 2015 07:14PM |
| Credit: | Karl Dyszynski and Hugo Vazquez Carames of SonicWall |
| Vulnerable: |
HP Virtual Connect Enterprise Manager 6.2 HP Virtual Connect Enterprise Manager 6.1 HP Virtual Connect Enterprise Manager 6.0 HP Version Control Repository Manager 7.4.1 HP Version Control Repository Manager 7.4 HP Version Control Repository Manager 7.3.4 HP Version Control Repository Manager 7.3.1 HP Version Control Repository Manager 7.3 HP Version Control Repository Manager 7.2.2 HP Version Control Repository Manager 7.2.1 HP Version Control Repository Manager 7.2 HP Version Control Repository Manager 7.4.0a HP Version Control Repository Manager 7.3.3 HP Version Control Repository Manager 7.3.2 HP Version Control Agent 7.3.5 HP Version Control Agent 7.3.4 HP Version Control Agent 7.3.3 HP Version Control Agent 7.3.1 HP Version Control Agent 7.3 HP Version Control Agent 7.2.2 HP Version Control Agent 7.2.1 HP Version Control Agent 7.2 HP Version Control Agent 2.1.5 HP Version Control Agent 7.3.2 HP Systems Insight Manager 7.1.1 HP Systems Insight Manager 7.4 HP Systems Insight Manager 7.3.2 HP Systems Insight Manager 7.3.1 HP Systems Insight Manager 7.3 HP Systems Insight Manager 7.2.2 HP Systems Insight Manager 7.2.1 HP Systems Insight Manager 7.2 HP Systems Insight Manager 7.0 HP Systems Insight Manager 6.3 HP Systems Insight Manager 6.2 HP Systems Insight Manager 6.1 HP Systems Insight Manager 6.0 HP Systems Insight Manager 5.3 HP Systems Insight Manager 5.0 HP Systems Insight Manager 4.2 HP System Management Homepage 7.3.2 HP System Management Homepage 7.2.3 HP System Management Homepage 7.2.2 HP System Management Homepage 7.2.1 HP System Management Homepage 7.2 HP System Management Homepage 7.1.2 HP System Management Homepage 7.1.1 HP System Management Homepage 6.2.2 7 HP System Management Homepage 3.2.7 HP System Management Homepage 3.0.2 .77 HP System Management Homepage 3.0 .68 HP System Management Homepage 3.0 .64 HP System Management Homepage 2.2.9 .1 HP System Management Homepage 2.2.8 HP System Management Homepage 2.2.6 HP System Management Homepage 2.1.15 HP System Management Homepage 2.1.12 HP System Management Homepage 2.1.11 HP System Management Homepage 2.1.10 HP System Management Homepage 2.1.9 HP System Management Homepage 2.1.8 HP System Management Homepage 2.1.7 HP System Management Homepage 2.1.6 HP System Management Homepage 2.1.5 HP System Management Homepage 2.1.4 HP System Management Homepage 2.1.3 HP System Management Homepage 2.1.2 HP System Management Homepage 2.1.1 HP System Management Homepage 2.1 HP System Management Homepage 2.0.2 HP System Management Homepage 2.0.1 HP System Management Homepage 2.0 HP System Management Homepage 7.4 HP System Management Homepage 7.3.3.1 HP System Management Homepage 7.3.1 HP System Management Homepage 7.3 HP System Management Homepage 7.2.4.1 HP System Management Homepage 7.2 HP System Management Homepage 7.1 HP System Management Homepage 7.0 HP System Management Homepage 6.3.0 HP System Management Homepage 6.3 HP System Management Homepage 6.2.0 HP System Management Homepage 6.2 HP System Management Homepage 6.0 HP System Management Homepage 3.2.2 HP System Management Homepage 3.0.1 HP Insight Orchestration 6.2 HP Insight Orchestration 6.1 HP Insight Orchestration 6.0 Apache Commons FileUpload 1.2.2 Apache Commons FileUpload 1.2.1 Apache Commons FileUpload 1.2 Apache Commons FileUpload 1.1.1 Apache Commons FileUpload 1.1 Apache Commons FileUpload 1.0 |
| Not Vulnerable: |
HP Virtual Connect Enterprise Manager SDK 7.5.0 HP Version Control Repository Manager 7.5.0 HP Version Control Agent 7.5.0 HP Systems Insight Manager 7.5.0 HP System Management Homepage 7.5 HP Insight Orchestration 7.5.0 |
Discussion
Apache Commons FileUpload CVE-2013-0248 Insecure Temporary File Creation Vulnerability
Apache Commons FileUpload is prone to an insecure temporary file-creation vulnerability because it creates temporary files in an insecure manner.
An attacker with local access could potentially exploit this issue to perform symbolic-link attacks, overwriting arbitrary files in the context of the affected application. Other attacks may also be possible.
Apache Commons FileUpload versions 1.0 through 1.2.2 are vulnerable; other versions may also be affected.
Apache Commons FileUpload is prone to an insecure temporary file-creation vulnerability because it creates temporary files in an insecure manner.
An attacker with local access could potentially exploit this issue to perform symbolic-link attacks, overwriting arbitrary files in the context of the affected application. Other attacks may also be possible.
Apache Commons FileUpload versions 1.0 through 1.2.2 are vulnerable; other versions may also be affected.
Exploit / POC
Apache Commons FileUpload CVE-2013-0248 Insecure Temporary File Creation Vulnerability
Attackers can use readily available tools and standard commands to exploit this issue.
Attackers can use readily available tools and standard commands to exploit this issue.
Solution / Fix
Apache Commons FileUpload CVE-2013-0248 Insecure Temporary File Creation Vulnerability
Solution:
Currently, we are not aware of any vendor-supplied patches. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Solution:
Currently, we are not aware of any vendor-supplied patches. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
References
Apache Commons FileUpload CVE-2013-0248 Insecure Temporary File Creation Vulnerability
References:
References:
- Apache Homepage (Apache Software Foundation)