SuSE Linux JavaRunt Configuration File Insecure Temporary File Vulnerability
BID:8779
Info
SuSE Linux JavaRunt Configuration File Insecure Temporary File Vulnerability
| Bugtraq ID: | 8779 |
| Class: | Design Error |
| CVE: | |
| Remote: | No |
| Local: | Yes |
| Published: | Oct 06 2003 12:00AM |
| Updated: | Oct 06 2003 12:00AM |
| Credit: | Discovery credited to Stefan Nordhausen. |
| Vulnerable: |
S.u.S.E. Linux Professional 7.3 |
| Not Vulnerable: |
S.u.S.E. Linux Professional 8.2 |
Discussion
SuSE Linux JavaRunt Configuration File Insecure Temporary File Vulnerability
A problem exists in the JavaRunt configuration file used by SuSEConfig. Because of this, it may be possible for a local attacker to gain elevated privileges via symlink attacks that corrupt system files with attacker-supplied data.
A problem exists in the JavaRunt configuration file used by SuSEConfig. Because of this, it may be possible for a local attacker to gain elevated privileges via symlink attacks that corrupt system files with attacker-supplied data.
Exploit / POC
SuSE Linux JavaRunt Configuration File Insecure Temporary File Vulnerability
Currently we are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Currently we are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution / Fix
SuSE Linux JavaRunt Configuration File Insecure Temporary File Vulnerability
Solution:
The vendor has acknowledged this issue, and stated that a fix is forthcoming.
-----
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution:
The vendor has acknowledged this issue, and stated that a fix is forthcoming.
-----
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
References
SuSE Linux JavaRunt Configuration File Insecure Temporary File Vulnerability
References:
References:
- S.u.S.E. Homepage (S.u.S.E.)
- Re: Local root exploit in SuSE Linux 8.2Pro (Roman Drahtmueller
)