GNU Readline '_rl_tropen()' Insecure Temporary File Handling Vulnerability
BID:66369
Info
GNU Readline '_rl_tropen()' Insecure Temporary File Handling Vulnerability
| Bugtraq ID: | 66369 |
| Class: | Design Error |
| CVE: |
CVE-2014-2524 |
| Remote: | No |
| Local: | Yes |
| Published: | Mar 14 2014 12:00AM |
| Updated: | Apr 13 2015 09:21PM |
| Credit: | Steve Kemp |
| Vulnerable: |
Mandriva Business Server 1 X86 64 Mandriva Business Server 1 GNU Readline 6.3 |
| Not Vulnerable: | |
Discussion
GNU Readline '_rl_tropen()' Insecure Temporary File Handling Vulnerability
GNU Readline is prone to an insecure temporary file-handling vulnerability.
An attacker with local access could potentially exploit this issue to perform symbolic-link attacks, overwriting arbitrary files in the context of the affected application.
GNU Readline 6.3 is vulnerable; other versions may also be affected.
GNU Readline is prone to an insecure temporary file-handling vulnerability.
An attacker with local access could potentially exploit this issue to perform symbolic-link attacks, overwriting arbitrary files in the context of the affected application.
GNU Readline 6.3 is vulnerable; other versions may also be affected.
Solution / Fix
GNU Readline '_rl_tropen()' Insecure Temporary File Handling Vulnerability
Solution:
Currently, we are not aware of any vendor-supplied patches. If you feel we are in error or are aware of more recent information, please mail us at: [email protected].
Mandriva Business Server 1 X86 64
Solution:
Currently, we are not aware of any vendor-supplied patches. If you feel we are in error or are aware of more recent information, please mail us at: [email protected].
Mandriva Business Server 1 X86 64
-
Mandriva lib64readline-devel-6.2-5.1.mbs1.x86_64.rpm
http://www.mandriva.com/en/downloads/ -
Mandriva lib64readline6-6.2-5.1.mbs1.x86_64.rpm
http://www.mandriva.com/en/downloads/ -
Mandriva readline-doc-6.2-5.1.mbs1.x86_64.rpm
http://www.mandriva.com/en/downloads/
References
GNU Readline '_rl_tropen()' Insecure Temporary File Handling Vulnerability
References:
References:
- Insecure usage of temporary files in GNU Readline (seclists.org)
- The GNU Readline Library (GNU)