syncevolution '/src/syncevo/installcheck-local.sh' Insecure Temporary File Creation Vulnerability
BID:65098
Info
syncevolution '/src/syncevo/installcheck-local.sh' Insecure Temporary File Creation Vulnerability
| Bugtraq ID: | 65098 |
| Class: | Design Error |
| CVE: |
CVE-2014-1639 |
| Remote: | No |
| Local: | Yes |
| Published: | Jan 22 2014 12:00AM |
| Updated: | Apr 13 2015 08:36PM |
| Credit: | Helmut Grohne |
| Vulnerable: | |
| Not Vulnerable: | |
Discussion
syncevolution '/src/syncevo/installcheck-local.sh' Insecure Temporary File Creation Vulnerability
syncevolution is prone to an insecure temporary file-creation vulnerability.
An attacker with local access could potentially exploit this issue to perform symbolic-link attacks, overwriting arbitrary files in the context of the affected application. Other attacks may also be possible.
syncevolution 1.0+ds1~beta2a-2 is vulnerable; other versions may also be affected.
syncevolution is prone to an insecure temporary file-creation vulnerability.
An attacker with local access could potentially exploit this issue to perform symbolic-link attacks, overwriting arbitrary files in the context of the affected application. Other attacks may also be possible.
syncevolution 1.0+ds1~beta2a-2 is vulnerable; other versions may also be affected.
Exploit / POC
syncevolution '/src/syncevo/installcheck-local.sh' Insecure Temporary File Creation Vulnerability
An attacker can exploit this issue using readily available tools.
An attacker can exploit this issue using readily available tools.
References
syncevolution '/src/syncevo/installcheck-local.sh' Insecure Temporary File Creation Vulnerability
References:
References:
- Debian Homepage (Debian)
- syncevolution Homepage (Tino Keitel)
- syncevolution: CVE-2014-1639: tmp file vulnerability (Helmut Grohne)