GNOME GDM CVE-2013-4169 Insecure Temporary File Creation Vulnerability
BID:62247
Info
GNOME GDM CVE-2013-4169 Insecure Temporary File Creation Vulnerability
| Bugtraq ID: | 62247 |
| Class: | Race Condition Error |
| CVE: |
CVE-2013-4169 |
| Remote: | No |
| Local: | Yes |
| Published: | Sep 05 2013 12:00AM |
| Updated: | Oct 04 2013 08:16AM |
| Credit: | Vladz |
| Vulnerable: |
Red Hat Enterprise Linux Desktop 5 client Red Hat Enterprise Linux 5 Server Oracle Enterprise Linux 5 MandrakeSoft Enterprise Server 5 x86_64 MandrakeSoft Enterprise Server 5 GNOME GDM 2.20.11 GNOME GDM 2.20.10 GNOME GDM 2.19.5 GNOME GDM 2.19.4 GNOME GDM 2.19.3 GNOME GDM 2.19.2 GNOME GDM 2.19.1 GNOME GDM 2.18.4 GNOME GDM 2.18.3 GNOME GDM 2.18.2 GNOME GDM 2.18.1 GNOME GDM 2.17.4 GNOME GDM 2.16.7 GNOME GDM 2.16.6 GNOME GDM 2.16.5 GNOME GDM 2.16.4 GNOME GDM 2.16.3 GNOME GDM 2.16.2 GNOME GDM 2.16.1 GNOME GDM 2.16 GNOME GDM 2.14.13 GNOME GDM 2.14.12 GNOME GDM 2.14.11 GNOME GDM 2.14.1 GNOME GDM 2.12 CentOS CentOS 5 Avaya Aura System Manager 6.0 SP1 Avaya Aura System Manager 6.0 Avaya Aura System Manager 5.2 Avaya Aura Session Manager 5.2 SP2 Avaya Aura Session Manager 5.2 SP1 Avaya Aura Session Manager 5.2 Avaya Aura Session Manager 1.1 Avaya Aura Session Manager 1.0 Avaya Aura Presence Services 6.1 Avaya Aura Presence Services 6.0 |
| Not Vulnerable: | |
Discussion
GNOME GDM CVE-2013-4169 Insecure Temporary File Creation Vulnerability
GDM is prone to an insecure temporary file-creation vulnerability because it creates temporary files in an insecure manner.
An attacker with local access could potentially exploit this issue to perform symbolic-link attacks, overwriting arbitrary files including root owned files in the context of the affected application. Other attacks may also be possible.
GDM versions prior to 2.21.1 are vulnerable.
GDM is prone to an insecure temporary file-creation vulnerability because it creates temporary files in an insecure manner.
An attacker with local access could potentially exploit this issue to perform symbolic-link attacks, overwriting arbitrary files including root owned files in the context of the affected application. Other attacks may also be possible.
GDM versions prior to 2.21.1 are vulnerable.
Exploit / POC
GNOME GDM CVE-2013-4169 Insecure Temporary File Creation Vulnerability
Currently, we are not aware of any working exploits. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Currently, we are not aware of any working exploits. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Solution / Fix
GNOME GDM CVE-2013-4169 Insecure Temporary File Creation Vulnerability
Solution:
Updates are available. Please see the references or vendor advisory for more information.
Solution:
Updates are available. Please see the references or vendor advisory for more information.
References
GNOME GDM CVE-2013-4169 Insecure Temporary File Creation Vulnerability
References:
References: