|
|
|
![]() |
Vulnerability Note VU#401808exuberant-ctags creates temporary files insecurelyOverviewSome versions of exuberant-ctags, a source code navigation utility, create and use temporary files insecurely, leading to local file corruption and possible denial-of-service.I. DescriptionExuberent-ctags is a source code navigation utility. It creates temporary files with predictable names in /tmp. Prior to creation, the utility does not check for existence of the temporary files. These files are created world-readable.II. ImpactBy creating symbolic links named as the temporary files, an attacker can cause exuberant-ctags to overwrite files writable by the user of exuberant-ctags. By creating similarly named files and protecting them against the user of exuberant-ctags, an attacker can deny use of this utility to a user.III. SolutionApply vendor patches; see the Systems Affected section below.Systems Affected
References
This vulnerability was first reported by Colin Phipps. This document was last modified by Tim Shimeall.
If you have feedback, comments, or additional information about this vulnerability, please send us
email. |
||||||||||||||||||||||||||||||||||||||||||||||
|
||||||||||||||||||||||||||||||||||||||||||||||||