SuSE YaST SuSEconfig.gnome-filesystem Local Insecure File Creation Symlink Vulnerability
BID:9411
Info
SuSE YaST SuSEconfig.gnome-filesystem Local Insecure File Creation Symlink Vulnerability
| Bugtraq ID: | 9411 |
| Class: | Origin Validation Error |
| CVE: |
CVE-2004-0064 |
| Remote: | No |
| Local: | Yes |
| Published: | Jan 13 2004 12:00AM |
| Updated: | Jan 13 2004 12:00AM |
| Credit: | Discovery of this vulnerability has been credited to l0om <[email protected]>. |
| Vulnerable: |
S.u.S.E. SuSEconfig.gnome-filesystem |
| Not Vulnerable: | |
Discussion
SuSE YaST SuSEconfig.gnome-filesystem Local Insecure File Creation Symlink Vulnerability
SuSEconfig.gnome-filesystem has been reported prone to an insecure file creation vulnerability that may be exploited to corrupt arbitrary files. The issue has been reported to present itself because the SuSEconfig.gnome-filesystem script will follow symbolic links when writing certain specific files.
SuSE Linux 9.0 has been reported to be prone to this issue, however, other versions could be affected as well.
SuSEconfig.gnome-filesystem has been reported prone to an insecure file creation vulnerability that may be exploited to corrupt arbitrary files. The issue has been reported to present itself because the SuSEconfig.gnome-filesystem script will follow symbolic links when writing certain specific files.
SuSE Linux 9.0 has been reported to be prone to this issue, however, other versions could be affected as well.
Exploit / POC
SuSE YaST SuSEconfig.gnome-filesystem Local Insecure File Creation Symlink Vulnerability
The following proof of concept exploit has been supplied:
The following proof of concept exploit has been supplied:
Solution / Fix
SuSE YaST SuSEconfig.gnome-filesystem Local Insecure File Creation Symlink Vulnerability
Solution:
The vendor has reported that this issue has been fixed in SuSE 9.0 stable.
Solution:
The vendor has reported that this issue has been fixed in SuSE 9.0 stable.
References
SuSE YaST SuSEconfig.gnome-filesystem Local Insecure File Creation Symlink Vulnerability
References:
References: