XBoard PXBoard Script Insecure Temporary File Creation Vulnerability
BID:9151
Info
XBoard PXBoard Script Insecure Temporary File Creation Vulnerability
| Bugtraq ID: | 9151 |
| Class: | Design Error |
| CVE: | |
| Remote: | No |
| Local: | Yes |
| Published: | Dec 03 2003 12:00AM |
| Updated: | Dec 03 2003 12:00AM |
| Credit: | Discovery of this vulnerability has been credited to Martin Macok <[email protected]>. |
| Vulnerable: |
XBoard XBoard 4.2.6 XBoard XBoard 4.2.5 |
| Not Vulnerable: |
XBoard XBoard 4.2.7 |
Discussion
XBoard PXBoard Script Insecure Temporary File Creation Vulnerability
It has been reported that the pxboard script utility shipped with XBoard may be prone to symlink attacks due to insecure temporary file creation. The problem occurs due to the affected script placing a file within the world accessible /tmp directory, and using a predictable naming convention.
As a result, an attacker may be capable of placing a symbolic link in the /tmp directory, likely pointing to a critical system file. This will effectively cause the script to carry out an operation on the file pointed to by the link, rather than the expected file.
It has been reported that the pxboard script utility shipped with XBoard may be prone to symlink attacks due to insecure temporary file creation. The problem occurs due to the affected script placing a file within the world accessible /tmp directory, and using a predictable naming convention.
As a result, an attacker may be capable of placing a symbolic link in the /tmp directory, likely pointing to a critical system file. This will effectively cause the script to carry out an operation on the file pointed to by the link, rather than the expected file.
Exploit / POC
XBoard PXBoard Script Insecure Temporary File Creation Vulnerability
Currently we are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Currently we are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution / Fix
XBoard PXBoard Script Insecure Temporary File Creation Vulnerability
Solution:
The vendor has released an update to address this issue:
XBoard XBoard 4.2.5
XBoard XBoard 4.2.6
Solution:
The vendor has released an update to address this issue:
XBoard XBoard 4.2.5
-
XBoard xboard-4.2.7.tar.gz
http://ftp.gnu.org/gnu/xboard/xboard-4.2.7.tar.gz
XBoard XBoard 4.2.6
-
XBoard xboard-4.2.7.tar.gz
http://ftp.gnu.org/gnu/xboard/xboard-4.2.7.tar.gz
References
XBoard PXBoard Script Insecure Temporary File Creation Vulnerability
References:
References:
- XBoard Homepage (XBoard)
- XBoard < 4.2.7: pxboard insecure tmp file handling (Martin Macok
)