Editor Login | Register
Ekle

> World > Security
Cecilia /tmp/csvers Insecure Temporary File Handling - Security - World -
CWRedLight
(Date : 16.04.2008 21:58:32)


Cecilia /tmp/csvers Insecure Temporary File Handling
Secunia Advisory: SA29832  
Release Date: 2008-04-16

Critical:
Not critical
Impact: Privilege escalation
Where: Local system
Solution Status: Unpatched

Software:Cecilia 2.x

Description:
Felipe Sateler has discovered a security issue in Cecilia, which can be exploited by malicious, local users to perform certain actions with escalated privileges.

The security issue is caused due to the "locateCsound()" function in lib/prefs.tcl using the temporary file "/tmp/csvers" in an insecure manner. This can be exploited to overwrite arbitrary files with the privileges of the user running Cecilia.

The security issue is confirmed in version 2.0.5. Other versions may also be affected.

Solution:
Restrict access to trusted people only.

Provided and/or discovered by:
Felipe Sateler

Original Advisory:
http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=476321












Derecelendir
Kaynak http://secunia.com/advisories/29832/
İçerik İhbarı
Bağlantılar: bilgininefendisi.net

Open Source Document Project AUP&TOS