ERoaster Local Insecure Temporary File Creation Vulnerability
BID:8350
Info
ERoaster Local Insecure Temporary File Creation Vulnerability
| Bugtraq ID: | 8350 |
| Class: | Access Validation Error |
| CVE: |
CVE-2003-0656 |
| Remote: | No |
| Local: | Yes |
| Published: | Aug 06 2003 12:00AM |
| Updated: | Jul 11 2009 10:56PM |
| Credit: | Vulnerability announced by Debian. |
| Vulnerable: |
eroaster eroaster 2.2 .0 eroaster eroaster 2.1 .0 eroaster eroaster 2.0 .0 |
| Not Vulnerable: |
eroaster eroaster 2.2 .0 eroaster eroaster 2.1 .0 |
Discussion
ERoaster Local Insecure Temporary File Creation Vulnerability
A problem has been reported in the secure creation of temporary files by the eroaster application. This may allow an attacker to overwrite files belonging to the eroaster user.
A problem has been reported in the secure creation of temporary files by the eroaster application. This may allow an attacker to overwrite files belonging to the eroaster user.
Exploit / POC
ERoaster Local Insecure Temporary File Creation Vulnerability
Currently we are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Currently we are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution / Fix
ERoaster Local Insecure Temporary File Creation Vulnerability
Solution:
Debian has made fixes available in advisory DSA 366-1. See referenced advisory for additional details.
Mandrake has released an advisory (MDKSA-2003:083) that addresses this issue. Please see the attached advisory for details on obtaining and applying fixes.
Gentoo Linux has released a security advisory (200309-04) to address this issue. Users who are affected by this issue are advised to do the following:
emerge sync
emerge eroaster
emerge clean
eroaster eroaster 2.1 .0
Solution:
Debian has made fixes available in advisory DSA 366-1. See referenced advisory for additional details.
Mandrake has released an advisory (MDKSA-2003:083) that addresses this issue. Please see the attached advisory for details on obtaining and applying fixes.
Gentoo Linux has released a security advisory (200309-04) to address this issue. Users who are affected by this issue are advised to do the following:
emerge sync
emerge eroaster
emerge clean
eroaster eroaster 2.1 .0
-
Debian eroaster_2.1.0.0.3-2woody1_all.deb
Debian GNU/Linux 3.0 alias woody
http://security.debian.org/pool/updates/main/e/eroaster/eroaster_2.1.0 .0.3-2woody1_all.deb -
Mandrake eroaster-2.1.0-6.1mdk.noarch.rpm
Mandrake Corporate Server 2.1
http://www.mandrakesecure.net/en/ftp.php -
Mandrake eroaster-2.1.0-6.1mdk.noarch.rpm
Mandrake Linux 9.0
http://www.mandrakesecure.net/en/ftp.php -
Mandrake eroaster-2.1.0-6.1mdk.noarch.rpm
Mandrake Linux 9.1
http://www.mandrakesecure.net/en/ftp.php
References
ERoaster Local Insecure Temporary File Creation Vulnerability
References:
References: