Vulnerabilities > CVE-2001-0774 - Unspecified vulnerability in Tripwire 1.3.1/2.2.1/2.3.0
Attack vector
UNKNOWN Attack complexity
UNKNOWN Privileges required
UNKNOWN Confidentiality impact
UNKNOWN Integrity impact
UNKNOWN Availability impact
UNKNOWN tripwire
nessus
Summary
Tripwire 1.3.1, 2.2.1 and 2.3.0 allows local users to overwrite arbitrary files and possible gain privileges via a symbolic link attack on temporary files.
Vulnerable Configurations
Part | Description | Count |
---|---|---|
Application | 3 |
Nessus
NASL family | Mandriva Local Security Checks |
NASL id | MANDRAKE_MDKSA-2001-064.NASL |
description | Jarno Juuskonen reported that a temporary file vulnerability exists in versions of Tripwire prior to 2.3.1-2. Because Tripwire opens/creates temporary files in /tmp without the O_EXCL flag during filesystem scanning and database updating, a malicious user could execute a symlink attack against the temporary files. This new version has all but one unsafe temporary file open fixed. It can still be used safely when using the new TEMPDIRECTORY configuration option, which is now set to /root/tmp. |
last seen | 2020-06-01 |
modified | 2020-06-02 |
plugin id | 13879 |
published | 2004-07-31 |
reporter | This script is Copyright (C) 2004-2019 Tenable Network Security, Inc. |
source | https://www.tenable.com/plugins/nessus/13879 |
title | Mandrake Linux Security Advisory : tripwire (MDKSA-2001:064) |
code |
|
References
- http://www.kb.cert.org/vuls/id/349019
- http://www.kb.cert.org/vuls/id/349019
- http://www.linux-mandrake.com/en/security/2001/MDKSA-2001-064.php3
- http://www.linux-mandrake.com/en/security/2001/MDKSA-2001-064.php3
- http://www.osvdb.org/1895
- http://www.osvdb.org/1895
- http://www.securityfocus.com/archive/1/195617
- http://www.securityfocus.com/archive/1/195617
- http://www.securityfocus.com/bid/3003
- http://www.securityfocus.com/bid/3003
- https://exchange.xforce.ibmcloud.com/vulnerabilities/6820
- https://exchange.xforce.ibmcloud.com/vulnerabilities/6820