|
SANE Insecure Temporary File Creation Vulnerability
SANE (Scanner Access Now Easy) is a scanner application programming interface. It will run on most Unix and Linux variants and is often front-ended by xSANE graphical user interface. SANE creates temporary files in the /tmp directory which have predictable file names. As a result, it is possible for a local user to create a symbolic link to any file that is write-accessible by the user executing SANE, and overwrite the contents of the file. The impact is that a local attacker may overwrite files, possibly resulting in a loss of critical data, a denial of service or escalation of privileges. |
|
|
Privacy Statement |