Vulnerabilities > CVE-2007-0476 - Unspecified vulnerability in Gentoo Linux 2.1.30/2.2.28/2.3.30
Attack vector
UNKNOWN Attack complexity
UNKNOWN Privileges required
UNKNOWN Confidentiality impact
UNKNOWN Integrity impact
UNKNOWN Availability impact
UNKNOWN gentoo
nessus
Summary
The gencert.sh script, when installing OpenLDAP before 2.1.30-r10, 2.2.x before 2.2.28-r7, and 2.3.x before 2.3.30-r2 as an ebuild in Gentoo Linux, does not create temporary directories in /tmp securely during emerge, which allows local users to overwrite arbitrary files via a symlink attack.
Vulnerable Configurations
Part | Description | Count |
---|---|---|
OS | 3 |
Nessus
NASL family | Gentoo Local Security Checks |
NASL id | GENTOO_GLSA-200701-19.NASL |
description | The remote host is affected by the vulnerability described in GLSA-200701-19 (OpenLDAP: Insecure usage of /tmp during installation) Tavis Ormandy of the Gentoo Linux Security Team has discovered that the file gencert.sh distributed with the Gentoo ebuild for OpenLDAP does not exit upon the existence of a directory in /tmp during installation allowing for directory traversal. Impact : A local attacker could create a symbolic link in /tmp and potentially overwrite arbitrary system files upon a privileged user emerging OpenLDAP. Workaround : There is no known workaround at this time. |
last seen | 2020-06-01 |
modified | 2020-06-02 |
plugin id | 24255 |
published | 2007-01-26 |
reporter | This script is Copyright (C) 2007-2019 Tenable Network Security, Inc. |
source | https://www.tenable.com/plugins/nessus/24255 |
title | GLSA-200701-19 : OpenLDAP: Insecure usage of /tmp during installation |
code |
|
References
- http://osvdb.org/31617
- http://osvdb.org/31617
- http://secunia.com/advisories/23881
- http://secunia.com/advisories/23881
- http://security.gentoo.org/glsa/glsa-200701-19.xml
- http://security.gentoo.org/glsa/glsa-200701-19.xml
- http://www.securityfocus.com/bid/22195
- http://www.securityfocus.com/bid/22195
- http://www.vupen.com/english/advisories/2007/0305
- http://www.vupen.com/english/advisories/2007/0305