|
|
|
Vulnerability Note VU#417216sort creates temporary files insecurelyOverviewThe sort utility creates temporary files insecurely, making sort subject to a denial-of-service attack.I. DescriptionThe UNIX sort utility creates temporary files with predictable names. The creation is done in a manner to prevent information loss via a symlink attack, but existence of the file will cause sort to fail, as it aborts when the creation fails.II. ImpactBy crashing the sort utility, an intruder may be able to block the operation of system administration programs.III. SolutionApply vendor patches; see the Systems Affected section below.Systems Affected
References
This vulnerability was identified by FreeBSD. This document was last modified by Tim Shimeall.
If you have feedback, comments, or additional information about this vulnerability, please send us
email. |
||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
|
|||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||