Debian rawstudio Package 'rs_filter_graph()' Function Insecure Temporary File Handling Vulnerability
BID:68671
Info
Debian rawstudio Package 'rs_filter_graph()' Function Insecure Temporary File Handling Vulnerability
| Bugtraq ID: | 68671 |
| Class: | Design Error |
| CVE: |
CVE-2014-4978 |
| Remote: | No |
| Local: | Yes |
| Published: | Jul 16 2014 12:00AM |
| Updated: | Jul 21 2014 12:19AM |
| Credit: | Steve Kemp |
| Vulnerable: | |
| Not Vulnerable: | |
Discussion
Debian rawstudio Package 'rs_filter_graph()' Function Insecure Temporary File Handling Vulnerability
Debian rawstudio package is prone to a vulnerability because it handles temporary files in an insecure manner.
Local attackers may be able to perform symbolic-link attacks to overwrite arbitrary files in the context of the affected application. Other attacks may also be possible.
rawstudio 2.0-1.1 is vulnerable; other versions may also be affected.
Debian rawstudio package is prone to a vulnerability because it handles temporary files in an insecure manner.
Local attackers may be able to perform symbolic-link attacks to overwrite arbitrary files in the context of the affected application. Other attacks may also be possible.
rawstudio 2.0-1.1 is vulnerable; other versions may also be affected.
Exploit / POC
Debian rawstudio Package 'rs_filter_graph()' Function Insecure Temporary File Handling Vulnerability
An attacker can use readily available commands to exploit this issue.
An attacker can use readily available commands to exploit this issue.
Solution / Fix
Debian rawstudio Package 'rs_filter_graph()' Function Insecure Temporary File Handling Vulnerability
Solution:
Currently, we are not aware of any vendor-supplied patches. If you feel we are in error or are aware of more recent information, please mail us at: [email protected].
Solution:
Currently, we are not aware of any vendor-supplied patches. If you feel we are in error or are aware of more recent information, please mail us at: [email protected].
References
Debian rawstudio Package 'rs_filter_graph()' Function Insecure Temporary File Handling Vulnerability
References:
References: