Search: Home Bugtraq Vulnerabilities Mailing Lists Jobs Tools Beta Programs

SANE Insecure Temporary File Creation Vulnerability

SANE (Scanner Access Now Easy) is a scanner application programming interface. It will run on most Unix and Linux variants and is often front-ended by xSANE graphical user interface.

SANE creates temporary files in the /tmp directory which have predictable file names. As a result, it is possible for a local user to create a symbolic link to any file that is write-accessible by the user executing SANE, and overwrite the contents of the file.

The impact is that a local attacker may overwrite files, possibly resulting in a loss of critical data, a denial of service or escalation of privileges.







 

Privacy Statement
Copyright 2008, SecurityFocus