GLSA Advocate

Joined: 12 May 2004 Posts: 2663
Posted: Thu Apr 10, 2008 9:26 pm Post subject: [ GLSA 200804-09 ] am-utils: Insecure temporary file creatio |
Gentoo Linux Security Advisory
Title: am-utils: Insecure temporary file creation (GLSA 200804-09)
Severity: normal
Exploitable: local
Date: April 10, 2008
Bug(s): #210158
ID: 200804-09
am-utils creates temporary files insecurely allowing local users to overwrite arbitrary files via a symlink attack.
am-utils is a collection of utilities for use with the Berkeley Automounter.
Affected Packages
Package: net-fs/am-utils
Vulnerable: < 6.1.5
Unaffected: >= 6.1.5
Architectures: All supported architectures
Tavis Ormandy discovered that, when creating temporary files, the 'expn' utility does not check whether the file already exists.
A local attacker could exploit the vulnerability via a symlink attack to overwrite arbitrary files.
There is no known workaround at this time.
All am-utils users should upgrade to the latest version: Code: | # emerge --sync
# emerge --ask --oneshot --verbose ">=net-fs/am-utils-6.1.5" |
CVE-2008-1078 |