Sun Solaris ASPPPLS Insecure Temporary File Creation Vulnerability

Solaris is the UNIX Operating System variant distributed and maintained by Sun Microsystems.

aspppls creates insecure temporary files. aspppls is a setuid root application that when executed will create temporary files with root privileges. This could result in a local attacker launching a symbolic link attack to overwrite root-owned files.

It should be noted that this vulnerability is likely related to Bugtraq ID 292 titled "Solaris aspppd Insecure Temporary File Creation Vulnerability."


 

Privacy Statement
Copyright 2010, SecurityFocus