Cdwrite Insecure Temporary File Vulnerability
BID:9165
Info
Cdwrite Insecure Temporary File Vulnerability
| Bugtraq ID: | 9165 |
| Class: | Access Validation Error |
| CVE: | |
| Remote: | No |
| Local: | Yes |
| Published: | Dec 06 2003 12:00AM |
| Updated: | Dec 06 2003 12:00AM |
| Credit: | Discovery is credited to Shaun Colley. |
| Vulnerable: |
Cdwrite Cdwrite 1.3 |
| Not Vulnerable: | |
Discussion
Cdwrite Insecure Temporary File Vulnerability
Cdwrite creates files in the temporary directory in an insecure manner. As a result, a local attacker may launch symlink attacks that could cause system files to be corrupted. This will most likely result in a denial of service or loss of data. This type of vulnerability could also result in privilege escalation if the attacker can influence what is written during the symbolic link attack.
Cdwrite creates files in the temporary directory in an insecure manner. As a result, a local attacker may launch symlink attacks that could cause system files to be corrupted. This will most likely result in a denial of service or loss of data. This type of vulnerability could also result in privilege escalation if the attacker can influence what is written during the symbolic link attack.
Exploit / POC
Cdwrite Insecure Temporary File Vulnerability
There is no exploit required.
There is no exploit required.
Solution / Fix
Cdwrite Insecure Temporary File Vulnerability
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
References
Cdwrite Insecure Temporary File Vulnerability
References:
References:
- Cdwrite Homepage (Cdwrite)
- cdwrite 1.3 insecure tmp file handling vulnerability. (=?iso-8859-1?q?Shaun=20Colley?=
)