|
Vulnerability Assessment & Network Security Forums |
|||||||||
If through a vulnerability assessment, a network security issue is detected for the vulnerability below, applying the appropriate security patches in a timely matter is very important. If you have detected that your system has already been compromised, following CERT's Network Security recovery document will assist with recommended steps for system recovery. Home >> Browse Vulnerability Assessment Database >> Gentoo Local Security Checks >> [GLSA-200406-18] gzip: Insecure creation of temporary files Vulnerability Assessment Details
|
[GLSA-200406-18] gzip: Insecure creation of temporary files |
||
gzip: Insecure creation of temporary files Detailed Explanation for this Vulnerability Assessment The remote host is affected by the vulnerability described in GLSA-200406-18 (gzip: Insecure creation of temporary files) The script gzexe included with gzip contains a bug in the code that handles tempfile creation. If the creation of a temp file fails when using gzexe fails instead of bailing out it executes the command given as argument. Impact This could lead to priviege escalation by running commands under the rights of the user running the self extracting file. Workaround There is no known workaround at this time. All users are encouraged to upgrade to the latest available version. Solution: All gzip users should upgrade to the latest stable version: # emerge sync # emerge -pv ">=app-arch/gzip-1.3.3-r4" # emerge ">=app-arch/gzip-1.3.3-r4" Additionally, once the upgrade is complete, all self extracting files created with earlier versions gzexe should be recreated, since the vulnerability is actually embedded in those executables. Network Security Threat Level: Medium Networks Security ID: Vulnerability Assessment Copyright: (C) 2005 Michel Arboi |
||
Cables, Connectors |
Intel Celeron 300 333 MHz SL2YP SL2X8 SL2WN SL2WN SL2Y2 vintage CPU GOLD
$10.95
Reveal KB-7061 Vintage mechanical keyboard READ BELOW
$65.00
Vintage Compaq 141649-004 2 Button PS/2 Gray Mouse M-S34 - FAST SHIPPING - NEW
$8.99
Vintage Desktop, HP Pavilion 6535, 128MB RAM, NO HDD, *READ*
$100.00
Vintage Classic Apple Macintosh System Boot Install Disk Floppy/CD *Pick Version
$10.39
AMD K6/PR2 166ALR AMD-K6-166ALR very rare PR2 Vintage CPU GOLD
$28.95
Vintage Black Microsoft intellimouse Optical USB Wheel Mouse 1.1/1.1a - EXC COND
$28.95
Voltage Blaster (Enhanced) -5V ISA AT ATX Power for Vintage Retro PCs US Seller
$12.95
Vintage Comfort Keyboard Systems Ergomagic Mechanical AT/PS2 Keyboard
$149.99
Vintage scorpius 980n plus Mechanical USB keyboard
$39.00
|
||
No Discussions have been posted on this vulnerability. |