OSVDB ID: 7413

Title: KAME Dump/Trace Location Issue

Info

Disclosure

Dec 16, 1999

Discovery

Unknown

Dates

Exploit

Unknown

Solution

Unknown

Description

KAME contains a flaw related to the default directory that many of its daemons write dump files and trace files to, which may allow an attacker to access sensitive system information, or possibly to modify that data. The bgpd, hroute6d, pim6dd, pim6sd, route6d, and rtsold daemons used the world-writeable /var/tmp directory for dump and trace files. No further details have been provided.

Classification

Location: Local Access Required
Attack Type: Unknown
Impact: Unknown
Exploit: Exploit Available
Disclosure: OSVDB Verified

Solution

Upgrade to version 1.345 or higher, as it has been reported to fix this vulnerability. It is also possible to correct the flaw by applying the vendor-supplied patch.

Products

KAME Project

KAME

1.344

References

Credit

  • OpenBSD - OpenBSD


Direct URL: http://osvdb.org/36218