Python logilab-common Package CVE-2014-1839 Insecure File Creation Vulnerability
BID:65899
Info
Python logilab-common Package CVE-2014-1839 Insecure File Creation Vulnerability
| Bugtraq ID: | 65899 |
| Class: | Input Validation Error |
| CVE: |
CVE-2014-1839 |
| Remote: | No |
| Local: | Yes |
| Published: | Jan 30 2014 12:00AM |
| Updated: | Apr 13 2015 10:11PM |
| Credit: | Jakub Wilk |
| Vulnerable: |
Python Software Foundation logilab-common 0.60.1 Oracle Solaris 11.1 openSUSE openSUSE 13.1 openSUSE openSUSE 12.3 |
| Not Vulnerable: |
Oracle Solaris 11.1.18.5.0 |
Discussion
Python logilab-common Package CVE-2014-1839 Insecure File Creation Vulnerability
Python logilab-common package is prone to an insecure file-creation vulnerability.
An attacker with local access could potentially exploit this issue to perform symbolic-link attacks.
Successfully mounting a symlink attack may allow the attacker to corrupt sensitive files or gain access to sensitive information. Other attacks may also be possible.
Python logilab-common 0.60.1 is vulnerable; other versions may also be affected.
Python logilab-common package is prone to an insecure file-creation vulnerability.
An attacker with local access could potentially exploit this issue to perform symbolic-link attacks.
Successfully mounting a symlink attack may allow the attacker to corrupt sensitive files or gain access to sensitive information. Other attacks may also be possible.
Python logilab-common 0.60.1 is vulnerable; other versions may also be affected.
Exploit / POC
Python logilab-common Package CVE-2014-1839 Insecure File Creation Vulnerability
An attacker can use readily available commands to exploit this issue.
An attacker can use readily available commands to exploit this issue.
Solution / Fix
Python logilab-common Package CVE-2014-1839 Insecure File Creation Vulnerability
Solution:
Updates are available. Please see the references or vendor advisory for more information.
Solution:
Updates are available. Please see the references or vendor advisory for more information.