OSVDB ID: 11539

Title: Gentoo Gentoolkit qpkg Symlink Arbitrary File Overwrite

Info

Disclosure

Nov 07, 2004

Discovery

Nov 07, 2004

Dates

Exploit

Unknown

Solution

Unknown

Description

Gentoo Gentoolkit contains a flaw that may allow a malicious user to overwrite arbitrary file reguardless of permissions. The issue is triggered when qpkg does not check permissions before writing to files in the /tmp directory occurs. It is possible that the flaw may allow a user to overwrite a file that has root privilages resulting in a loss of integrity.

Classification

Location: Local Access Required
Attack Type: Input Manipulation, Race Condition
Impact: Loss of Integrity
Exploit: Exploit Unknown

Solution

Upgrade to version "0.2.0_pre8-r1" or higher, as it has been reported to fix this vulnerability. An upgrade is required as there are no known workarounds.

Products

Gentoo Foundation, Inc.

Gentoolkit

0.1.0
0.2.0

References

Credit

Unknown or Incomplete



Direct URL: http://osvdb.org/36218