S-PLUS For Unix Insecure Temporary File Vulnerabilities
BID:6530
Info
S-PLUS For Unix Insecure Temporary File Vulnerabilities
| Bugtraq ID: | 6530 |
| Class: | Design Error |
| CVE: | |
| Remote: | No |
| Local: | Yes |
| Published: | Jan 06 2003 12:00AM |
| Updated: | Jan 06 2003 12:00AM |
| Credit: | Discovery of this issue is credited to Paul Szabo. |
| Vulnerable: |
Insightful S-PLUS for Unix 6.0 |
| Not Vulnerable: | |
Discussion
S-PLUS For Unix Insecure Temporary File Vulnerabilities
S-PLUS for Unix is prone to a number of insecure temporary file creation vulnerabilities. These issues exist in some of the S-PLUS Spqe binary and various shell scripts.
S-PLUS creates temporary files using predictable names. Additionally, when these files are created symbolic links will be followed. If the attacker can anticipate the names of these temporary files, it is possible to lauch symbolic link attacks which may result in file corruption.
S-PLUS for Unix is prone to multiple instances of this vulnerability.
S-PLUS for Unix is prone to a number of insecure temporary file creation vulnerabilities. These issues exist in some of the S-PLUS Spqe binary and various shell scripts.
S-PLUS creates temporary files using predictable names. Additionally, when these files are created symbolic links will be followed. If the attacker can anticipate the names of these temporary files, it is possible to lauch symbolic link attacks which may result in file corruption.
S-PLUS for Unix is prone to multiple instances of this vulnerability.
Exploit / POC
S-PLUS For Unix Insecure Temporary File Vulnerabilities
There is no exploit code required.
There is no exploit code required.
Solution / Fix
S-PLUS For Unix Insecure Temporary File Vulnerabilities
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
References
S-PLUS For Unix Insecure Temporary File Vulnerabilities
References:
References:
- S-PLUS for Unix Homepage (Insightful)
- S-plus /tmp usage ([email protected] (Paul Szabo))