Vulnerabilities > CVE-2008-0673 - Unspecified vulnerability in Tintin Tintin++ and Wintin++
Attack vector
UNKNOWN Attack complexity
UNKNOWN Privileges required
UNKNOWN Confidentiality impact
UNKNOWN Integrity impact
UNKNOWN Availability impact
UNKNOWN tintin
nessus
Summary
TinTin++ 1.97.9 and WinTin++ 1.97.9 open files on the basis of an inbound file-transfer request, before the user has an opportunity to decline the request, which allows remote attackers to truncate arbitrary files in the top level of a home directory.
Vulnerable Configurations
Part | Description | Count |
---|---|---|
Application | 2 |
Nessus
NASL family | Gentoo Local Security Checks |
NASL id | GENTOO_GLSA-201111-07.NASL |
description | The remote host is affected by the vulnerability described in GLSA-201111-07 (TinTin++: Multiple vulnerabilities) Multiple vulnerabilities have been discovered in TinTin++. Please review the CVE identifiers referenced below for details. Impact : Remote unauthenticated attackers may be able to execute arbitrary code with the privileges of the TinTin++ process, cause a Denial of Service, or truncate arbitrary files in the top level of the home directory belonging to the user running the TinTin++ process. Workaround : There is no known workaround at this time. |
last seen | 2020-06-01 |
modified | 2020-06-02 |
plugin id | 56903 |
published | 2011-11-22 |
reporter | This script is Copyright (C) 2011-2018 Tenable Network Security, Inc. |
source | https://www.tenable.com/plugins/nessus/56903 |
title | GLSA-201111-07 : TinTin++: Multiple vulnerabilities |
code |
|
References
- http://aluigi.altervista.org/adv/rintintin-adv.txt
- http://aluigi.altervista.org/adv/rintintin-adv.txt
- http://secunia.com/advisories/28833
- http://secunia.com/advisories/28833
- http://security.gentoo.org/glsa/glsa-201111-07.xml
- http://security.gentoo.org/glsa/glsa-201111-07.xml
- http://securityreason.com/securityalert/3632
- http://securityreason.com/securityalert/3632
- http://www.securityfocus.com/archive/1/487687/100/0/threaded
- http://www.securityfocus.com/archive/1/487687/100/0/threaded
- http://www.securityfocus.com/bid/27660
- http://www.securityfocus.com/bid/27660
- http://www.vupen.com/english/advisories/2008/0449
- http://www.vupen.com/english/advisories/2008/0449