Clang 'Scan-Build' Utility Insecure Temporary File Handling Vulnerability
BID:66989
Info
Clang 'Scan-Build' Utility Insecure Temporary File Handling Vulnerability
| Bugtraq ID: | 66989 |
| Class: | Design Error |
| CVE: |
CVE-2014-2893 |
| Remote: | No |
| Local: | Yes |
| Published: | Apr 16 2014 12:00AM |
| Updated: | Jun 18 2014 03:53AM |
| Credit: | Jakub Wilk |
| Vulnerable: | |
| Not Vulnerable: | |
Discussion
Clang 'Scan-Build' Utility Insecure Temporary File Handling Vulnerability
Clang is prone to an insecure temporary file-handling vulnerability.
An attacker with local access could potentially exploit this issue to perform symbolic-link attacks, overwriting arbitrary files or information disclosure in the context of the affected application.
Clang 3.5 is vulnerable; other versions may also be affected.
Clang is prone to an insecure temporary file-handling vulnerability.
An attacker with local access could potentially exploit this issue to perform symbolic-link attacks, overwriting arbitrary files or information disclosure in the context of the affected application.
Clang 3.5 is vulnerable; other versions may also be affected.
Exploit / POC
Clang 'Scan-Build' Utility Insecure Temporary File Handling Vulnerability
An attacker can use readily available commands to exploit this issue.
An attacker can use readily available commands to exploit this issue.
Solution / Fix
Clang 'Scan-Build' Utility Insecure Temporary File Handling Vulnerability
Solution:
Updates are available. Please see the references or vendor advisory for more information.
Solution:
Updates are available. Please see the references or vendor advisory for more information.
References
Clang 'Scan-Build' Utility Insecure Temporary File Handling Vulnerability
References:
References: