SEMI/WEMI Insecure Temporary File Creation Vulnerability
BID:8115
Info
SEMI/WEMI Insecure Temporary File Creation Vulnerability
| Bugtraq ID: | 8115 |
| Class: | Access Validation Error |
| CVE: |
CVE-2003-0440 |
| Remote: | No |
| Local: | Yes |
| Published: | Jul 07 2003 12:00AM |
| Updated: | Jul 11 2009 10:56PM |
| Credit: | This vulnerability has been disclosed in a Debian advisory. |
| Vulnerable: |
semi semi 1.14.5 semi semi 1.14.3 Debian Linux 3.0 |
| Not Vulnerable: | |
Discussion
SEMI/WEMI Insecure Temporary File Creation Vulnerability
SEMI/WEMI have been reported prone to an insecure temporary file creation vulnerability. As a result, it may be possible for local attackers to corrupt files owned by the user who is invoking a version of Emacs that is linked to the vulnerable library.
It should be noted that the impact of this vulnerability might be exaggerated by the fact that attackers may potentially influence content that will be added to the target file.
SEMI/WEMI have been reported prone to an insecure temporary file creation vulnerability. As a result, it may be possible for local attackers to corrupt files owned by the user who is invoking a version of Emacs that is linked to the vulnerable library.
It should be noted that the impact of this vulnerability might be exaggerated by the fact that attackers may potentially influence content that will be added to the target file.
Exploit / POC
SEMI/WEMI Insecure Temporary File Creation Vulnerability
Currently we are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Currently we are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution / Fix
SEMI/WEMI Insecure Temporary File Creation Vulnerability
Solution:
Debian has released an advisory (DSA 339-1) and fixes to address this issue. Further information regarding applying fixes for stable and unstable versions of Debian Linux can be found in the referenced advisory.
Yellow Dog has released an advisory with fixes to address this issue.
Red Hat has released advisory RHSA-2003:234-01 to address this issue. See referenced advisory for additional details and fix information. RHSA-2003:231-10 was also released to provide updates for Red Hat Enterprise distributions. Enterprise fixes are available exclusively from the Red Hat Network.
Gentoo has released an advisory and fixes. Users should perform the following commands to upgrade:
emerge sync
emerge semi
emerge clean
semi semi 1.14.3
Debian Linux 3.0
Solution:
Debian has released an advisory (DSA 339-1) and fixes to address this issue. Further information regarding applying fixes for stable and unstable versions of Debian Linux can be found in the referenced advisory.
Yellow Dog has released an advisory with fixes to address this issue.
Red Hat has released advisory RHSA-2003:234-01 to address this issue. See referenced advisory for additional details and fix information. RHSA-2003:231-10 was also released to provide updates for Red Hat Enterprise distributions. Enterprise fixes are available exclusively from the Red Hat Network.
Gentoo has released an advisory and fixes. Users should perform the following commands to upgrade:
emerge sync
emerge semi
emerge clean
semi semi 1.14.3
-
Yellow Dog wl-2.10.1-1.1.noarch.rpm
ftp://ftp.yellowdoglinux.com/pub/yellowdog/updates/yellowdog-3.0/ppc/w l-2.10.1-1.1.noarch.rpm -
Yellow Dog wl-common-2.10.1-1.1.noarch.rpm
ftp://ftp.yellowdoglinux.com/pub/yellowdog/updates/yellowdog-3.0/ppc/w l-common-2.10.1-1.1.noarch.rpm -
Yellow Dog wl-xemacs-2.10.1-1.1.noarch.rpm
ftp://ftp.yellowdoglinux.com/pub/yellowdog/updates/yellowdog-3.0/ppc/w l-xemacs-2.10.1-1.1.noarch.rpm
Debian Linux 3.0
-
Debian semi_1.14.3.cvs.2001.08.10-1woody2_all.deb
http://security.debian.org/pool/updates/main/s/semi/semi_1.14.3.cvs.20 01.08.10-1woody2_all.deb -
Debian wemi_1.14.0.20010802wemiko-1.3_all.deb
http://security.debian.org/pool/updates/main/w/wemi/wemi_1.14.0.200108 02wemiko-1.3_all.deb
References
SEMI/WEMI Insecure Temporary File Creation Vulnerability
References:
References:
- RHSA-2003:231-10 Updated semi packages fix vulnerability (Red Hat)
- Updated wl packages are available (Yellow Dog Linux)