Vulnerabilities > CVE-2002-0662 - Unspecified vulnerability in DAN Mueth Scrollkeeper
Attack vector
UNKNOWN Attack complexity
UNKNOWN Privileges required
UNKNOWN Confidentiality impact
UNKNOWN Integrity impact
UNKNOWN Availability impact
UNKNOWN dan-mueth
nessus
Summary
scrollkeeper-get-cl in ScrollKeeper 0.3 to 0.3.11 allows local users to create and overwrite files via a symlink attack on the scrollkeeper-tempfile.x temporary files.
Vulnerable Configurations
Nessus
NASL family | Debian Local Security Checks |
NASL id | DEBIAN_DSA-160.NASL |
description | Spybreak discovered a problem in scrollkeeper, a free electronic cataloging system for documentation. The scrollkeeper-get-cl program creates temporary files in an insecure manner in /tmp using guessable filenames. Since scrollkeeper is called automatically when a user logs into a Gnome session, an attacker with local access can easily create and overwrite files as another user. |
last seen | 2020-06-01 |
modified | 2020-06-02 |
plugin id | 14997 |
published | 2004-09-29 |
reporter | This script is Copyright (C) 2004-2019 Tenable Network Security, Inc. |
source | https://www.tenable.com/plugins/nessus/14997 |
title | Debian DSA-160-1 : scrollkeeper - insecure temporary file creation |
code |
|
Packetstorm
data source | https://packetstormsecurity.com/files/download/29538/scrollkeeper.txt |
id | PACKETSTORM:29538 |
last seen | 2016-12-05 |
published | 2002-09-04 |
reporter | Spybreak |
source | https://packetstormsecurity.com/files/29538/scrollkeeper.txt.html |
title | scrollkeeper.txt |
Redhat
advisories |
|
References
- http://marc.info/?l=bugtraq&m=103098575826031&w=2
- http://marc.info/?l=bugtraq&m=103098575826031&w=2
- http://marc.info/?l=bugtraq&m=103115387102294&w=2
- http://marc.info/?l=bugtraq&m=103115387102294&w=2
- http://www.debian.org/security/2002/dsa-160
- http://www.debian.org/security/2002/dsa-160
- http://www.iss.net/security_center/static/10002.php
- http://www.iss.net/security_center/static/10002.php
- http://www.redhat.com/support/errata/RHSA-2002-186.html
- http://www.redhat.com/support/errata/RHSA-2002-186.html
- http://www.securityfocus.com/bid/5602
- http://www.securityfocus.com/bid/5602