Search: Home Bugtraq Vulnerabilities Mailing Lists Jobs Tools Beta Programs

Crip Helper Script Insecure Temporary File Creation Vulnerability

The crip helper scripts create temporary files in an insecure manner. An attacker will local access could potentially exploit this issue to overwrite files in the context of the application.

Exploitation would most likely result in loss of data or a denial of service if critical files are overwritten in the attack. There is also an unconfirmed potential for privilege escalation if the attacker can write custom data in the attack.

This issue is known to affect crip 3.5. Other releases may also be affected.







 

Privacy Statement
Copyright 2008, SecurityFocus