OSVDB ID: 11538

Title: Portage dispatch-conf Symlink Arbitrary File Overwrite

Info

Disclosure

Nov 07, 2004

Discovery

Nov 07, 2004

Dates

Exploit

Unknown

Solution

Unknown

Description

Gentoo Portage contains a flaw that may allow a malicious user to to overwrite arbitrary file reguardless of permissions. The issue is triggered when "dispatch-conf" script does not check permissions before writing to files in the /tmp directory occurs. It is possible that the flaw may allow overwrite a file that has root privilages resulting in a loss of integrity.

Classification

Location: Local Access Required
Attack Type: Input Manipulation, Race Condition
Impact: Loss of Integrity
Exploit: Exploit Unknown

Solution

Upgrade to version 2.0.51-r3 or higher, as it has been reported to fix this vulnerability. An upgrade is required as there are no known workarounds.

Products

Gentoo Foundation, Inc.

Portage

1.0.0
2.0.0
2.0.51-r2

References

Credit

Unknown or Incomplete



Direct URL: http://osvdb.org/36218