Vulnerabilities > CVE-2004-2502 - Symbolic Link vulnerability in IM-Switch Insecure Temporary File Handling
Attack vector
LOCAL Attack complexity
LOW Privileges required
NONE Confidentiality impact
NONE Integrity impact
PARTIAL Availability impact
NONE Summary
im-switch before 11.4-46.1 in Fedora Core 2 allows local users to overwrite arbitrary files via a symlink attack on the imswitcher[PID] temporary file.
Vulnerable Configurations
Part | Description | Count |
---|---|---|
Application | 1 |
Exploit-Db
description | IM-Switch Insecure Temporary File Handling Symbolic Link Vulnerability. CVE-2004-2502. Local exploit for linux platform |
id | EDB-ID:24278 |
last seen | 2016-02-02 |
modified | 2004-07-13 |
published | 2004-07-13 |
reporter | SEKINE Tatsuo |
source | https://www.exploit-db.com/download/24278/ |
title | IM-Switch Insecure Temporary File Handling Symbolic Link Vulnerability |
References
- http://bugzilla.redhat.com/bugzilla/show_bug.cgi?id=126940
- http://packetstormsecurity.org/0407-advisories/fedora_im-switch_tempfile_race.txt
- http://secunia.com/advisories/12037
- http://www.osvdb.org/7772
- http://www.securityfocus.com/bid/10717
- https://exchange.xforce.ibmcloud.com/vulnerabilities/16682