Red Hat CloudForms Management Engine CVE-2014-3486 Insecure Temporary File Creation Vulnerability
BID:68300
Info
Red Hat CloudForms Management Engine CVE-2014-3486 Insecure Temporary File Creation Vulnerability
| Bugtraq ID: | 68300 |
| Class: | Design Error |
| CVE: |
CVE-2014-3486 |
| Remote: | No |
| Local: | Yes |
| Published: | Jul 01 2014 12:00AM |
| Updated: | Jul 01 2014 12:00AM |
| Credit: | Kurt Seifried |
| Vulnerable: | |
| Not Vulnerable: | |
Discussion
Red Hat CloudForms Management Engine CVE-2014-3486 Insecure Temporary File Creation Vulnerability
Red Hat CloudForms Management Engine is prone to an insecure temporary file-creation vulnerability.
An attacker can exploit this vulnerability to execute arbitrary commands as the root user. Other attacks may also be possible.
Red Hat CloudForms Management Engine is prone to an insecure temporary file-creation vulnerability.
An attacker can exploit this vulnerability to execute arbitrary commands as the root user. Other attacks may also be possible.
Exploit / POC
Red Hat CloudForms Management Engine CVE-2014-3486 Insecure Temporary File Creation Vulnerability
An attacker can use readily available commands to exploit this issue.
An attacker can use readily available commands to exploit this issue.
Solution / Fix
Red Hat CloudForms Management Engine CVE-2014-3486 Insecure Temporary File Creation Vulnerability
Solution:
Updates are available. Please see the references or vendor advisory for more information.
Solution:
Updates are available. Please see the references or vendor advisory for more information.
References
Red Hat CloudForms Management Engine CVE-2014-3486 Insecure Temporary File Creation Vulnerability
References:
References: