Apache Tomcat CVE-2013-1976 Insecure Temporary File Handling Vulnerability
BID:60186
Info
Apache Tomcat CVE-2013-1976 Insecure Temporary File Handling Vulnerability
| Bugtraq ID: | 60186 |
| Class: | Design Error |
| CVE: |
CVE-2013-1976 |
| Remote: | No |
| Local: | Yes |
| Published: | May 28 2013 12:00AM |
| Updated: | Feb 20 2014 12:30AM |
| Credit: | Simon Fayer of Imperial College London |
| Vulnerable: |
Red Hat JBoss Enterprise Web Server for RHEL 6 1.0 Red Hat JBoss Enterprise Web Server for RHEL 5 Server 1.0 Red Hat Enterprise Linux Workstation Optional 6 Red Hat Enterprise Linux Workstation 6 Red Hat Enterprise Linux Server Optional 6 Red Hat Enterprise Linux Server 6 Red Hat Enterprise Linux HPC Node Optional 6 Red Hat Enterprise Linux Desktop Optional 6 Oracle Enterprise Linux 6.2 Oracle Enterprise Linux 6 Oracle Enterprise Linux 5 CentOS CentOS 6 CentOS CentOS 5 Avaya Aura System Manager 6.1.3 Avaya Aura System Manager 6.1.2 Avaya Aura System Manager 6.1.1 Apache Software Foundation Tomcat 0 |
| Not Vulnerable: | |
Discussion
Apache Tomcat CVE-2013-1976 Insecure Temporary File Handling Vulnerability
Apache Tomcat is prone to a vulnerability because it handles temporary files in an insecure manner.
Local attackers can exploit this issue to cause denial of service conditions or to execute arbitrary code with the privileges of the system user; other attacks may also be possible.
Apache Tomcat is prone to a vulnerability because it handles temporary files in an insecure manner.
Local attackers can exploit this issue to cause denial of service conditions or to execute arbitrary code with the privileges of the system user; other attacks may also be possible.
Exploit / POC
Apache Tomcat CVE-2013-1976 Insecure Temporary File Handling Vulnerability
An attacker can use readily available commands to exploit this issue.
An attacker can use readily available commands to exploit this issue.
Solution / Fix
Apache Tomcat CVE-2013-1976 Insecure Temporary File Handling Vulnerability
Solution:
Reportedly the issue is fixed, however Symantec has not confirmed this. Please contact the vendor for more information.
Solution:
Reportedly the issue is fixed, however Symantec has not confirmed this. Please contact the vendor for more information.
References
Apache Tomcat CVE-2013-1976 Insecure Temporary File Handling Vulnerability
References:
References:
- Apache Tomcat Homepage (Apache)