esearch eupdatedb symlink attack
| esearch-eupdatedb-symlink (16584) |
Description:
esearch creates the esearchdb.py.tmp temporary file insecurely. A local attacker could create a symbolic link from this file to an arbitrary file, which could allow the attacker to create files on the system.
Consequences:
File Manipulation
Remedy:
Upgrade to the latest version of esearch (0.6.2 or later), as listed in GLSA 200407-01. See References.
References:
- BID-10644: Esearch eupdatedb Symbolic Link Vulnerability
- CVE-2004-0655: eupdatedb in esearch 0.6.1 and earlier allows local users to create arbitrary files via a symlink attack on the esearchdb.py.tmp temporary file.
- GLSA-200407-01: Esearch: Insecure temp file handling
Platforms Affected:
- David Peter esearch prior to 0.6.2
- Gentoo Linux
Reported:
Jul 01, 2004
The information within this database may change without notice. Use of this information constitutes acceptance for use in an AS IS condition. There are NO warranties, implied or otherwise, with regard to this information or its use. Any use of this information is at the user's risk. In no event shall the author/distributor (IBM Internet Security Systems X-Force) be held liable for any damages whatsoever arising out of or in connection with the use or spread of this information.
For corrections or additions please email xforce@iss.net
