9base Insecure Temporary File Creation Vulnerability
BID:65483
Info
9base Insecure Temporary File Creation Vulnerability
| Bugtraq ID: | 65483 |
| Class: | Design Error |
| CVE: |
CVE-2014-1935 |
| Remote: | No |
| Local: | Yes |
| Published: | Jan 31 2014 12:00AM |
| Updated: | Jan 31 2014 12:00AM |
| Credit: | Jakub Wilk |
| Vulnerable: |
9base 9base 1.6-6 |
| Not Vulnerable: | |
Discussion
9base Insecure Temporary File Creation Vulnerability
9base creates temporary files in an insecure manner.
An attacker with local access could potentially exploit this issue to perform symbolic-link attacks.
Successfully mounting a symlink attack may allow the attacker to delete or corrupt sensitive files, which may result in a denial of service. Other attacks may also be possible.
9base creates temporary files in an insecure manner.
An attacker with local access could potentially exploit this issue to perform symbolic-link attacks.
Successfully mounting a symlink attack may allow the attacker to delete or corrupt sensitive files, which may result in a denial of service. Other attacks may also be possible.
Exploit / POC
9base Insecure Temporary File Creation Vulnerability
An attacker uses readily available commands to exploit this issue.
An attacker uses readily available commands to exploit this issue.
Solution / Fix
9base Insecure Temporary File Creation Vulnerability
Solution:
Reportedly the issue is fixed, however Symantec has not confirmed this. Please contact the vendor for more information.
Solution:
Reportedly the issue is fixed, however Symantec has not confirmed this. Please contact the vendor for more information.
References
9base Insecure Temporary File Creation Vulnerability
References:
References: