Tomb Insecure Temporary File Handling and Security Bypass Vulnerabilities
BID:70655
Info
Tomb Insecure Temporary File Handling and Security Bypass Vulnerabilities
| Bugtraq ID: | 70655 |
| Class: | Design Error |
| CVE: | |
| Remote: | Yes |
| Local: | Yes |
| Published: | Oct 20 2014 12:00AM |
| Updated: | Oct 20 2014 12:00AM |
| Credit: | Michael Scherer |
| Vulnerable: | |
| Not Vulnerable: | |
Discussion
Tomb Insecure Temporary File Handling and Security Bypass Vulnerabilities
Tomb is prone to an insecure temporary file-handling vulnerability and a security-bypass vulnerability.
An attacker can exploit these issues to perform symbolic-link attacks, overwriting arbitrary files in the context of the affected application, bypass certain security restrictions, and perform unauthorized actions. This may aid in further attacks.
Tomb is prone to an insecure temporary file-handling vulnerability and a security-bypass vulnerability.
An attacker can exploit these issues to perform symbolic-link attacks, overwriting arbitrary files in the context of the affected application, bypass certain security restrictions, and perform unauthorized actions. This may aid in further attacks.
Exploit / POC
Tomb Insecure Temporary File Handling and Security Bypass Vulnerabilities
An attacker can exploit these issues through standard tools and commands. Attackers require local interactive access to exploit insecure temporary file-handling vulnerability.
An attacker can exploit these issues through standard tools and commands. Attackers require local interactive access to exploit insecure temporary file-handling vulnerability.
Solution / Fix
Tomb Insecure Temporary File Handling and Security Bypass Vulnerabilities
Solution:
Currently, we are not aware of any vendor-supplied patches. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Solution:
Currently, we are not aware of any vendor-supplied patches. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
References
Tomb Insecure Temporary File Handling and Security Bypass Vulnerabilities
References:
References: