Python vos Insecure Temporary File Creation Vulnerability
BID:69684
Info
Python vos Insecure Temporary File Creation Vulnerability
| Bugtraq ID: | 69684 |
| Class: | Design Error |
| CVE: | |
| Remote: | No |
| Local: | Yes |
| Published: | Sep 09 2014 12:00AM |
| Updated: | Sep 09 2014 12:00AM |
| Credit: | Kurt Seifried |
| Vulnerable: | |
| Not Vulnerable: | |
Discussion
Python vos Insecure Temporary File Creation Vulnerability
Python vos is prone to an insecure temporary file-creation vulnerability.
An attacker with local access could potentially exploit this issue to perform symbolic-link attacks, overwriting arbitrary files in the context of the affected application. Other attacks may also be possible.
vos 1.10.4 is vulnerable; other versions may also be affected.
Python vos is prone to an insecure temporary file-creation vulnerability.
An attacker with local access could potentially exploit this issue to perform symbolic-link attacks, overwriting arbitrary files in the context of the affected application. Other attacks may also be possible.
vos 1.10.4 is vulnerable; other versions may also be affected.
Exploit / POC
Python vos Insecure Temporary File Creation Vulnerability
An attacker uses readily available commands to exploit this issue.
An attacker uses readily available commands to exploit this issue.
References
Python vos Insecure Temporary File Creation Vulnerability
References:
References: