Vulnerabilities > CVE-2005-3137 - Unspecified vulnerability in GNU Cfengine 1.6.5
Attack vector
LOCAL Attack complexity
LOW Privileges required
NONE Confidentiality impact
NONE Integrity impact
PARTIAL Availability impact
NONE Summary
The (1) cfmailfilter and (2) cfcron.in files for cfengine 1.6.5 allow local users to overwrite arbitrary files via a symlink attack on temporary files, a different vulnerability than CVE-2005-2960.
Vulnerable Configurations
Part | Description | Count |
---|---|---|
Application | 1 |
Nessus
NASL family FreeBSD Local Security Checks NASL id FREEBSD_PKG_8688D5CD328C11DAA2630001020EED82.NASL description A Debian Security Advisory reports : Javier Fernandez-Sanguino Pena discovered several insecure temporary file uses in cfengine, a tool for configuring and maintaining networked machines, that can be exploited by a symlink attack to overwrite arbitrary files owned by the user executing cfengine, which is probably root. last seen 2020-06-01 modified 2020-06-02 plugin id 21464 published 2006-05-13 reporter This script is Copyright (C) 2006-2019 and is owned by Tenable, Inc. or an Affiliate thereof. source https://www.tenable.com/plugins/nessus/21464 title FreeBSD : cfengine -- arbitrary file overwriting vulnerability (8688d5cd-328c-11da-a263-0001020eed82) NASL family Mandriva Local Security Checks NASL id MANDRAKE_MDKSA-2005-184.NASL description Javier Fernández-Sanguino Peña discovered several insecure temporary file uses in cfengine <= 1.6.5 and <= 2.1.16 which allows local users to overwrite arbitrary files via a symlink attack on temporary files used by vicf.in. (CVE-2005-2960) In addition, Javier discovered the cfmailfilter and cfcron.in files for cfengine <= 1.6.5 allow local users to overwrite arbitrary files via a symlink attack on temporary files (CVE-2005-3137) The updated packages have been patched to address this issue. last seen 2020-06-01 modified 2020-06-02 plugin id 20043 published 2005-10-19 reporter This script is Copyright (C) 2005-2019 Tenable Network Security, Inc. source https://www.tenable.com/plugins/nessus/20043 title Mandrake Linux Security Advisory : cfengine (MDKSA-2005:184) NASL family Debian Local Security Checks NASL id DEBIAN_DSA-836.NASL description Javier Fernandez-Sanguino Pena discovered insecure temporary file use in cfengine2, a tool for configuring and maintaining networked machines, that can be exploited by a symlink attack to overwrite arbitrary files owned by the user executing cfengine, which is probably root. The oldstable distribution (woody) is not affected by this problem. last seen 2020-06-01 modified 2020-06-02 plugin id 19805 published 2005-10-05 reporter This script is Copyright (C) 2005-2019 Tenable Network Security, Inc. source https://www.tenable.com/plugins/nessus/19805 title Debian DSA-836-1 : cfengine2 - insecure temporary files NASL family Ubuntu Local Security Checks NASL id UBUNTU_USN-198-1.NASL description Javier Fernandez-Sanguino Pena discovered that several tools in the cfengine package (vicf, cfmailfilter, and cfcron) create and use temporary files in an insecure way. A local attacker could exploit this with a symlink attack to create or overwrite arbitrary files with the privileges of the user running the cfengine program. Note that Tenable Network Security has extracted the preceding description block directly from the Ubuntu security advisory. Tenable has attempted to automatically clean and format it as much as possible without introducing additional issues. last seen 2020-06-01 modified 2020-06-02 plugin id 20612 published 2006-01-15 reporter Ubuntu Security Notice (C) 2005-2019 Canonical, Inc. / NASL script (C) 2006-2016 Tenable Network Security, Inc. source https://www.tenable.com/plugins/nessus/20612 title Ubuntu 4.10 / 5.04 : cfengine vulnerabilities (USN-198-1) NASL family Debian Local Security Checks NASL id DEBIAN_DSA-835.NASL description Javier Fernandez-Sanguino Pena discovered several insecure temporary file uses in cfengine, a tool for configuring and maintaining networked machines, that can be exploited by a symlink attack to overwrite arbitrary files owned by the user executing cfengine, which is probably root. last seen 2020-06-01 modified 2020-06-02 plugin id 19804 published 2005-10-05 reporter This script is Copyright (C) 2005-2019 Tenable Network Security, Inc. source https://www.tenable.com/plugins/nessus/19804 title Debian DSA-835-1 : cfengine - insecure temporary files
References
- http://bugs.gentoo.org/show_bug.cgi?id=107871
- http://groups.google.com/group/gnu.cfengine.help/browse_thread/thread/fc25e7d98f8ba401/38151ed821803be0#38151ed821803be0
- http://secunia.com/advisories/17037/
- http://secunia.com/advisories/17038
- http://secunia.com/advisories/17040
- http://secunia.com/advisories/17142
- http://secunia.com/advisories/17182
- http://www.debian.org/security/2005/dsa-835
- http://www.debian.org/security/2005/dsa-836
- http://www.mandriva.com/security/advisories?name=MDKSA-2005:184
- http://www.securityfocus.com/bid/14994
- http://www.ubuntu.com/usn/usn-198-1
- https://exchange.xforce.ibmcloud.com/vulnerabilities/22489