AIM Sniff Temporary File Symlink Attack Vulnerability
BID:9653
Info
AIM Sniff Temporary File Symlink Attack Vulnerability
| Bugtraq ID: | 9653 |
| Class: | Access Validation Error |
| CVE: |
CVE-2004-0279 |
| Remote: | No |
| Local: | Yes |
| Published: | Feb 12 2004 12:00AM |
| Updated: | Jul 12 2009 02:06AM |
| Credit: | Discover of this vulnerability has been credited to Martin <[email protected]>. |
| Vulnerable: |
AIM Sniff AIM Sniff 0.9 b AIM Sniff AIM Sniff 0.9 AIM Sniff AIM Sniff 0.8 AIM Sniff AIM Sniff 0.7 AIM Sniff AIM Sniff 0.6 |
| Not Vulnerable: |
AIM Sniff AIM Sniff 0.9 d |
Discussion
AIM Sniff Temporary File Symlink Attack Vulnerability
AIM Sniff has been reported prone to a Symbolic link vulnerability. The issue presents itself, because the aimSniff.pl script creates temporary files in an insecure manner.
An attacker may exploit this issue to corrupt arbitrary files. This corruption may potentially result in the elevation of privileges, or in a system wide denial of service.
It has been reported that a user will require root privileges to invoke the affected script; this may magnify the impact of this vulnerability.
AIM Sniff has been reported prone to a Symbolic link vulnerability. The issue presents itself, because the aimSniff.pl script creates temporary files in an insecure manner.
An attacker may exploit this issue to corrupt arbitrary files. This corruption may potentially result in the elevation of privileges, or in a system wide denial of service.
It has been reported that a user will require root privileges to invoke the affected script; this may magnify the impact of this vulnerability.
Exploit / POC
Solution / Fix
AIM Sniff Temporary File Symlink Attack Vulnerability
Solution:
The vendor has supplied an upgrade to address this issue:
AIM Sniff AIM Sniff 0.6
AIM Sniff AIM Sniff 0.7
AIM Sniff AIM Sniff 0.8
AIM Sniff AIM Sniff 0.9
AIM Sniff AIM Sniff 0.9 b
Solution:
The vendor has supplied an upgrade to address this issue:
AIM Sniff AIM Sniff 0.6
-
AIM Sniff AIM Sniff 0.9d
http://prdownloads.sourceforge.net/aimsniff/aimsniff-0.9d.tar.gz?downl oad
AIM Sniff AIM Sniff 0.7
-
AIM Sniff AIM Sniff 0.9d
http://prdownloads.sourceforge.net/aimsniff/aimsniff-0.9d.tar.gz?downl oad
AIM Sniff AIM Sniff 0.8
-
AIM Sniff AIM Sniff 0.9d
http://prdownloads.sourceforge.net/aimsniff/aimsniff-0.9d.tar.gz?downl oad
AIM Sniff AIM Sniff 0.9
-
AIM Sniff AIM Sniff 0.9d
http://prdownloads.sourceforge.net/aimsniff/aimsniff-0.9d.tar.gz?downl oad
AIM Sniff AIM Sniff 0.9 b
-
AIM Sniff AIM Sniff 0.9d
http://prdownloads.sourceforge.net/aimsniff/aimsniff-0.9d.tar.gz?downl oad