xbindkeys-config '/tmp/xbindkeysrc-tmp' Insecure Temporary File Creation Vulnerability
BID:71868
CVE-2014-9513 |Info
xbindkeys-config '/tmp/xbindkeysrc-tmp' Insecure Temporary File Creation Vulnerability
| Bugtraq ID: | 71868 |
| Class: | Design Error |
| CVE: |
CVE-2014-9513 |
| Remote: | No |
| Local: | Yes |
| Published: | Jan 03 2015 12:00AM |
| Updated: | Jan 03 2015 12:00AM |
| Credit: | Steve Kemp |
| Vulnerable: |
Debian xbindkeys-config 0.1.3-2 |
| Not Vulnerable: | |
Discussion
xbindkeys-config '/tmp/xbindkeysrc-tmp' Insecure Temporary File Creation Vulnerability
xbindkeys-config is prone to an insecure temporary file-creation vulnerability because it creates temporary files in an insecure manner.
An attacker with local access could potentially exploit this issue to perform symbolic-link attacks, overwriting arbitrary files in the context of the affected application. Other attacks may also be possible.
xbindkeys-config is prone to an insecure temporary file-creation vulnerability because it creates temporary files in an insecure manner.
An attacker with local access could potentially exploit this issue to perform symbolic-link attacks, overwriting arbitrary files in the context of the affected application. Other attacks may also be possible.
Exploit / POC
xbindkeys-config '/tmp/xbindkeysrc-tmp' Insecure Temporary File Creation Vulnerability
An attacker can use readily available commands and tools to exploit this issue.
An attacker can use readily available commands and tools to exploit this issue.
Solution / Fix
xbindkeys-config '/tmp/xbindkeysrc-tmp' Insecure Temporary File Creation Vulnerability
Solution:
Currently, we are not aware of any vendor-supplied patches. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Solution:
Currently, we are not aware of any vendor-supplied patches. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
References
xbindkeys-config '/tmp/xbindkeysrc-tmp' Insecure Temporary File Creation Vulnerability
References:
References:
- #772473 xbindkeys-config: CVE-2014-9513 (Debian)
- xbindkeys-config Homepage (Debian)