eyeD3 Insecure Temporary File Creation Vulnerability
BID:65480
Info
eyeD3 Insecure Temporary File Creation Vulnerability
| Bugtraq ID: | 65480 |
| Class: | Design Error |
| CVE: |
CVE-2014-1934 |
| Remote: | No |
| Local: | Yes |
| Published: | Jan 29 2014 12:00AM |
| Updated: | Apr 13 2015 08:39PM |
| Credit: | Jakub Wilk |
| Vulnerable: | |
| Not Vulnerable: | |
Discussion
eyeD3 Insecure Temporary File Creation Vulnerability
eyeD3 creates temporary files in an insecure manner.
An attacker with local access could potentially exploit this issue to perform symbolic-link attacks.
Successfully mounting a symlink attack may allow the attacker to delete or corrupt sensitive files, which may result in a denial of service. Other attacks may also be possible.
eyeD3 versions 0.6.1 through 0.6.18 are vulnerable.
eyeD3 creates temporary files in an insecure manner.
An attacker with local access could potentially exploit this issue to perform symbolic-link attacks.
Successfully mounting a symlink attack may allow the attacker to delete or corrupt sensitive files, which may result in a denial of service. Other attacks may also be possible.
eyeD3 versions 0.6.1 through 0.6.18 are vulnerable.
Exploit / POC
eyeD3 Insecure Temporary File Creation Vulnerability
An attacker uses readily available commands to exploit this issue.
An attacker uses readily available commands to exploit this issue.
Solution / Fix
eyeD3 Insecure Temporary File Creation Vulnerability
Solution:
Currently, we are not aware of any vendor-supplied patches. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Solution:
Currently, we are not aware of any vendor-supplied patches. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
References
eyeD3 Insecure Temporary File Creation Vulnerability
References:
References: