Debian devscripts 'uscan' CVE-2013-7325 Insecure Temporary File Creation Vulnerability
BID:65542
Info
Debian devscripts 'uscan' CVE-2013-7325 Insecure Temporary File Creation Vulnerability
| Bugtraq ID: | 65542 |
| Class: | Design Error |
| CVE: |
CVE-2013-7325 |
| Remote: | No |
| Local: | Yes |
| Published: | Feb 06 2014 12:00AM |
| Updated: | Feb 06 2014 12:00AM |
| Credit: | The vendor reported this issue. |
| Vulnerable: |
Debian devscripts 2.13.5 |
| Not Vulnerable: |
Debian devscripts 2.13.9 |
Discussion
Debian devscripts 'uscan' CVE-2013-7325 Insecure Temporary File Creation Vulnerability
Debian devscripts is prone to a vulnerability because it creates temporary files in an insecure manner.
An attacker with local access could potentially exploit this issue to perform symbolic-link attacks, overwriting arbitrary files in the context of the affected application.
Successfully mounting a symlink attack may allow the attacker to delete or corrupt sensitive files, which may result in obtaining sensitive information. Other attacks may also be possible.
Debian devscripts is prone to a vulnerability because it creates temporary files in an insecure manner.
An attacker with local access could potentially exploit this issue to perform symbolic-link attacks, overwriting arbitrary files in the context of the affected application.
Successfully mounting a symlink attack may allow the attacker to delete or corrupt sensitive files, which may result in obtaining sensitive information. Other attacks may also be possible.
References
Debian devscripts 'uscan' CVE-2013-7325 Insecure Temporary File Creation Vulnerability
References:
References:
- devscripts Package (Debian)
- Re: [notification] CVE-2013-6888: uscan: remote code execution (SecLists.Org)