Vulnerabilities > CVE-2005-2918 - Unspecified vulnerability in Gtkdiskfree

047910
CVSS 5.0 - MEDIUM
Attack vector
NETWORK
Attack complexity
LOW
Privileges required
NONE
Confidentiality impact
NONE
Integrity impact
PARTIAL
Availability impact
NONE
network
low complexity
gtkdiskfree
nessus

Summary

The open_cmd_tube function in mount.c for gtkdiskfree 1.9.3 and earlier allows local users to overwrite arbitrary files via a symlink attack on the gtkdiskfree temporary file.

Vulnerable Configurations

Part Description Count
Application
Gtkdiskfree
1

Nessus

  • NASL familyGentoo Local Security Checks
    NASL idGENTOO_GLSA-200510-01.NASL
    descriptionThe remote host is affected by the vulnerability described in GLSA-200510-01 (gtkdiskfree: Insecure temporary file creation) Eric Romang discovered that gtkdiskfree insecurely creates a predictable temporary file to handle command output. Impact : A local attacker could create a symbolic link in the temporary files directory, pointing to a valid file somewhere on the filesystem. When gtkdiskfree is executed, this would result in the file being overwritten with the rights of the user running the application. Workaround : There is no known workaround at this time.
    last seen2020-06-01
    modified2020-06-02
    plugin id19821
    published2005-10-05
    reporterThis script is Copyright (C) 2005-2019 Tenable Network Security, Inc.
    sourcehttps://www.tenable.com/plugins/nessus/19821
    titleGLSA-200510-01 : gtkdiskfree: Insecure temporary file creation
  • NASL familyDebian Local Security Checks
    NASL idDEBIAN_DSA-822.NASL
    descriptionEric Romang discovered that gtkdiskfree, a GNOME program that shows free and used space on filesystems, creates a temporary file in an insecure fashion.
    last seen2020-06-01
    modified2020-06-02
    plugin id19791
    published2005-10-05
    reporterThis script is Copyright (C) 2005-2019 Tenable Network Security, Inc.
    sourcehttps://www.tenable.com/plugins/nessus/19791
    titleDebian DSA-822-1 : gtkdiskfree - insecure temporary file creation