Python luigi Multiple Insecure Temporary File Creation Vulnerabilities
BID:69687
Info
Python luigi Multiple Insecure Temporary File Creation Vulnerabilities
| Bugtraq ID: | 69687 |
| Class: | Design Error |
| CVE: | |
| Remote: | No |
| Local: | Yes |
| Published: | Sep 09 2014 12:00AM |
| Updated: | Sep 09 2014 12:00AM |
| Credit: | Kurt Seifried |
| Vulnerable: | |
| Not Vulnerable: | |
Discussion
Python luigi Multiple Insecure Temporary File Creation Vulnerabilities
Python luigi is prone to multiple insecure temporary file-creation vulnerabilities.
An attacker with local access could potentially exploit these issues to perform symbolic-link attacks, overwriting arbitrary files in the context of the affected application. Other attacks may also be possible.
luigi 1.0.17 is vulnerable; other versions may also be affected.
Python luigi is prone to multiple insecure temporary file-creation vulnerabilities.
An attacker with local access could potentially exploit these issues to perform symbolic-link attacks, overwriting arbitrary files in the context of the affected application. Other attacks may also be possible.
luigi 1.0.17 is vulnerable; other versions may also be affected.
Exploit / POC
Python luigi Multiple Insecure Temporary File Creation Vulnerabilities
An attacker uses readily available commands to exploit these issues.
An attacker uses readily available commands to exploit these issues.
References
Python luigi Multiple Insecure Temporary File Creation Vulnerabilities
References:
References: