GNU Automake Insecure Temporary File Handling Vulnerability
BID:69777
Info
GNU Automake Insecure Temporary File Handling Vulnerability
| Bugtraq ID: | 69777 |
| Class: | Design Error |
| CVE: | |
| Remote: | No |
| Local: | Yes |
| Published: | Sep 04 2014 12:00AM |
| Updated: | Sep 04 2014 12:00AM |
| Credit: | Vasyl Kaigorodov |
| Vulnerable: |
GNU Automake 1.14 |
| Not Vulnerable: | |
Discussion
GNU Automake Insecure Temporary File Handling Vulnerability
GNU Automake is prone to an insecure temporary file-handling vulnerability.
An attacker with local access could potentially exploit this issue to perform symbolic-link attacks.
GNU Automake is prone to an insecure temporary file-handling vulnerability.
An attacker with local access could potentially exploit this issue to perform symbolic-link attacks.
Exploit / POC
GNU Automake Insecure Temporary File Handling Vulnerability
An attacker can use readily available commands to exploit this issue.
An attacker can use readily available commands to exploit this issue.
Solution / Fix
GNU Automake Insecure Temporary File Handling Vulnerability
Solution:
Updates are available. Please see the references or vendor advisory for more information.
Solution:
Updates are available. Please see the references or vendor advisory for more information.
References
GNU Automake Insecure Temporary File Handling Vulnerability
References:
References:
- Automake Homepage (GNU)
- CVE request: automake: insecure use of /tmp in install-sh (Vasyl Kaigorodov)