mindi Temporary File Creation Vulnerabilities
BID:8332
Info
mindi Temporary File Creation Vulnerabilities
| Bugtraq ID: | 8332 |
| Class: | Access Validation Error |
| CVE: |
CVE-2003-0617 |
| Remote: | No |
| Local: | Yes |
| Published: | Aug 02 2003 12:00AM |
| Updated: | Jul 11 2009 10:56PM |
| Credit: | Announced by Debian. |
| Vulnerable: |
Hugo Rabson Mindi 0.58 r5 |
| Not Vulnerable: | |
Discussion
mindi Temporary File Creation Vulnerabilities
Debian has reported that Mindi is affected by several temporary file creation vulnerabilities that could allow for corruption of local files and, possibly, elevation of privileges. Throughout it's operation, mindi creates numerous files in /tmp with predictable filenames. Because /tmp is world-writeable, symbolic link attacks are possible.
Debian has reported that Mindi is affected by several temporary file creation vulnerabilities that could allow for corruption of local files and, possibly, elevation of privileges. Throughout it's operation, mindi creates numerous files in /tmp with predictable filenames. Because /tmp is world-writeable, symbolic link attacks are possible.
Exploit / POC
mindi Temporary File Creation Vulnerabilities
Currently we are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Currently we are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution / Fix
mindi Temporary File Creation Vulnerabilities
Solution:
Debian has issued fixes. See advisory DSA-362-1 in the references section.
Gentoo Linux has released a security advisory (200309-05) to address this issue. Users who are affected by this issue are advised to do the following:
emerge sync
emerge mindi
emerge clean
Hugo Rabson Mindi 0.58 r5
Solution:
Debian has issued fixes. See advisory DSA-362-1 in the references section.
Gentoo Linux has released a security advisory (200309-05) to address this issue. Users who are affected by this issue are advised to do the following:
emerge sync
emerge mindi
emerge clean
Hugo Rabson Mindi 0.58 r5
-
Debian mindi_0.58.r5-1woody1_i386.deb
Debian GNU/Linux 3.0 (woody)
http://security.debian.org/pool/updates/main/m/mindi/mindi_0.58.r5-1wo ody1_i386.deb
References
mindi Temporary File Creation Vulnerabilities
References:
References: