Symantec AntiVirus Scan Engine For Red Hat Linux Insecure Temporary File Vulnerabilities

BID:9662

Info

Symantec AntiVirus Scan Engine For Red Hat Linux Insecure Temporary File Vulnerabilities

Bugtraq ID: 9662
Class: Race Condition Error
CVE: CVE-2004-0217
Remote: No
Local: Yes
Published: Feb 16 2004 12:00AM
Updated: Jul 12 2009 03:06AM
Credit: Discovery is credited to Dr. Peter Bieringer.
Vulnerable: Symantec AntiVirus Scan Engine for Red Hat Linux 4.3
Symantec AntiVirus Scan Engine for Red Hat Linux 4.0
Not Vulnerable:

Discussion

Symantec AntiVirus Scan Engine For Red Hat Linux Insecure Temporary File Vulnerabilities

Multiple issues related to insecure creation of temporary files were reported in Symantec AntiVirus Scan Engine for Red Hat Linux. These issues are exposed during installation and prior to the software being run for the first time. This could potentially allow malicious local users to corrupt files in the context of the user invoking the software, most likely resulting in a denial of service or loss of data.

Exploit / POC

Symantec AntiVirus Scan Engine For Red Hat Linux Insecure Temporary File Vulnerabilities

There is no exploit required.

Solution / Fix

Symantec AntiVirus Scan Engine For Red Hat Linux Insecure Temporary File Vulnerabilities

Solution:
A build update for Symantec AntiVirus Scan Engine 4.3 correcting this issue is available. Users can obtain the update through their support channels. An update for Symantec Java LiveUpdate that is strengthened against this issue will be available soon.

An advisory detailing the remediation of this vulnerability is available at:

http://www.symantec.com/avcenter/security/Content/2004.03.23.html

References

Symantec AntiVirus Scan Engine For Red Hat Linux Insecure Temporary File Vulnerabilities

References:
© CVE.report 2026 |

Use of this information constitutes acceptance for use in an AS IS condition. There are NO warranties, implied or otherwise, with regard to this information or its use. Any use of this information is at the user's risk. It is the responsibility of user to evaluate the accuracy, completeness or usefulness of any information, opinion, advice or other content. EACH USER WILL BE SOLELY RESPONSIBLE FOR ANY consequences of his or her direct or indirect use of this web site. ALL WARRANTIES OF ANY KIND ARE EXPRESSLY DISCLAIMED. This site will NOT BE LIABLE FOR ANY DIRECT, INDIRECT or any other kind of loss.

CVE, CWE, and OVAL are registred trademarks of The MITRE Corporation and the authoritative source of CVE content is MITRE's CVE web site. This site includes MITRE data granted under the following license.

Free CVE JSON API cve.report/api

CVE.report and Source URL Uptime Status status.cve.report