Slackware netconfig temporary file Vulnerability
BID:81
Info
Slackware netconfig temporary file Vulnerability
| Bugtraq ID: | 81 |
| Class: | Access Validation Error |
| CVE: | |
| Remote: | No |
| Local: | Yes |
| Published: | Apr 06 1998 12:00AM |
| Updated: | Apr 06 1998 12:00AM |
| Credit: | Made public by neonhaze <[email protected]> and <[email protected]> in the BugTraq mailing list. |
| Vulnerable: |
Slackware Linux 3.4 |
| Not Vulnerable: | |
Discussion
Slackware netconfig temporary file Vulnerability
netconfig creates the file /tmp/tmpmsg insecurely and follows symbolic links. An attacker can create a symbolic link from /tmp/tmpmsg to any file and wait for root to run the program. This will clober the target file. The file created has permissions -rw-r--r--.
netconfig creates the file /tmp/tmpmsg insecurely and follows symbolic links. An attacker can create a symbolic link from /tmp/tmpmsg to any file and wait for root to run the program. This will clober the target file. The file created has permissions -rw-r--r--.
Solution / Fix
Slackware netconfig temporary file Vulnerability
Solution:
Upgrade to any version of Slackware Linux post version 3.4.
Solution:
Upgrade to any version of Slackware Linux post version 3.4.
References
Slackware netconfig temporary file Vulnerability
References:
References: