SnortCenter Insecure Temporary Filename Vulnerability
BID:6108
Info
SnortCenter Insecure Temporary Filename Vulnerability
| Bugtraq ID: | 6108 |
| Class: | Access Validation Error |
| CVE: | |
| Remote: | No |
| Local: | Yes |
| Published: | Nov 05 2002 12:00AM |
| Updated: | Nov 05 2002 12:00AM |
| Credit: | Discovery of vulnerability credited to Clint Byrum. |
| Vulnerable: |
SnortCenter SnortCenter 0.9.5 |
| Not Vulnerable: |
SnortCenter SnortCenter 0.9.6 |
Discussion
SnortCenter Insecure Temporary Filename Vulnerability
A vulnerability has been discovered in SnortCenter v0.9.5.
It has been reported that SnortCenter creates temporary files using predictable file names.
By anticipating the name of a temporary file a local attacker may be able to corrupt sensitive data by creating a symbolic link to a SnortCenter writable system resource.
It is not yet known whether versions prior to v0.9.5 are affected by this issue.
A vulnerability has been discovered in SnortCenter v0.9.5.
It has been reported that SnortCenter creates temporary files using predictable file names.
By anticipating the name of a temporary file a local attacker may be able to corrupt sensitive data by creating a symbolic link to a SnortCenter writable system resource.
It is not yet known whether versions prior to v0.9.5 are affected by this issue.