Search: Home Bugtraq Vulnerabilities Mailing Lists Jobs Tools Beta Programs

KSymoops KSymoops-GZNM Insecure Temporary File Handling Symbolic Link Vulnerability

Ksymoops ships with several scripts, one of these scripts is 'ksymoops-gznm'. It is reported that the 'ksymoops-gznm' script is prone to a local insecure temporary file handling symbolic link vulnerability. This issue is due to a design error that allows the application to insecurely write to a temporary file that is created with a predictable file name. The script will write to this file before verifying its existence; this would facilitate a symbolic link attack.







 

Privacy Statement
Copyright 2009, SecurityFocus