Search: Home Bugtraq Vulnerabilities Mailing Lists Jobs Tools Beta Programs

CVSup-Mirror Insecure Temporary Files Vulnerability

cvsup-mirror is prone to a vulnerability which may enable local attackers to corrupt critical system files.

cvsup-mirror creates a file entitled 'cvsupd.out' in the /var/tmp/ directory. A local attacker could create a symbolic link in /var/tmp with the same name, pointing to critical system files.

Any actions performed by cvsup-mirror on 'cvsupd.out' will instead be performed on files pointed to by the symbolic link. This may result in a denial of service if critical files are overwritten, and may potentially allow for privilege escalation.







 

Privacy Statement
Copyright 2008, SecurityFocus