Slackware liloconfig-color temporary file Vulnerability
BID:77
Info
Slackware liloconfig-color temporary file Vulnerability
| Bugtraq ID: | 77 |
| Class: | Access Validation Error |
| CVE: | |
| Remote: | No |
| Local: | Unknown |
| Published: | Apr 06 1998 12:00AM |
| Updated: | Apr 06 1998 12:00AM |
| Credit: | Made public by neonhaze <[email protected]> and <[email protected]> in the BugTraq mailing list. |
| Vulnerable: |
Slackware Linux 3.4 |
| Not Vulnerable: | |
Discussion
Slackware liloconfig-color temporary file Vulnerability
liloconfig-color creates the file /tmp/reply insecurely and follows symbolic
links. An attacker can create a symbolic link from /tmp/reply to any file
and wait for root to run the program. This will clober the target file.
The file created has permissions -rw-r--r--.
liloconfig-color creates the file /tmp/reply insecurely and follows symbolic
links. An attacker can create a symbolic link from /tmp/reply to any file
and wait for root to run the program. This will clober the target file.
The file created has permissions -rw-r--r--.
Solution / Fix
Slackware liloconfig-color temporary file Vulnerability
Solution:
Currently the SecurityFocus staff are not aware of any vendor supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected].
Solution:
Currently the SecurityFocus staff are not aware of any vendor supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected].