Eric Raymond cstrings tempnam() Insecure Temporary File Creation Vulnerability

BID:9391

Info

Eric Raymond cstrings tempnam() Insecure Temporary File Creation Vulnerability

Bugtraq ID: 9391
Class: Race Condition Error
CVE:
Remote: No
Local: Yes
Published: Dec 29 2003 12:00AM
Updated: Dec 29 2003 12:00AM
Credit: This issue was discovered by the vendor.
Vulnerable: Eric Raymond cstrings 2.2
Not Vulnerable: Eric Raymond cstrings 2.3

Discussion

Eric Raymond cstrings tempnam() Insecure Temporary File Creation Vulnerability

cstrings creates temporary files in an insecure manner using the tempnam() function, potentially creating an exploitable race condition that could be leveraged by a malicious local user.

An attacker could leverage this issue by creating a malicious symbolic link (using the name of the anticipated temporary file) that points to another file that is owned by the user who is expected to run with software. When the software is run, it may perform operations on the file pointed to by the symbolic link instead of the legitimate output file. This could theoretically lead to file corruption, most likely resulting in destruction of data and denial of service.

Exploit / POC

Eric Raymond cstrings tempnam() Insecure Temporary File Creation Vulnerability

Currently we are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.

Solution / Fix

Eric Raymond cstrings tempnam() Insecure Temporary File Creation Vulnerability

Solution:
This issue has been addressed in cstrings 2.3.


Eric Raymond cstrings 2.2

References

Eric Raymond cstrings tempnam() Insecure Temporary File Creation Vulnerability

References:

© CVE.report 2026

Use of this information constitutes acceptance for use in an AS IS condition. There are NO warranties, implied or otherwise, with regard to this information or its use. Any use of this information is at the user's risk. It is the responsibility of user to evaluate the accuracy, completeness or usefulness of any information, opinion, advice or other content. EACH USER WILL BE SOLELY RESPONSIBLE FOR ANY consequences of his or her direct or indirect use of this web site. ALL WARRANTIES OF ANY KIND ARE EXPRESSLY DISCLAIMED. This site will NOT BE LIABLE FOR ANY DIRECT, INDIRECT or any other kind of loss.

CVE, CWE, and OVAL are registred trademarks of The MITRE Corporation and the authoritative source of CVE content is MITRE's CVE web site. This site includes MITRE data granted under the following license.

Free CVE JSON API cve.report/api

CVE.report and Source URL Uptime Status status.cve.report