LMBench: Insecure temporary file usage
1.
Gentoo Linux Security Advisory
Version Information
| Advisory Reference |
GLSA 200909-10 / lmbench |
| Release Date |
September 09, 2009 |
| Latest Revision |
September 09, 2009: 01 |
| Impact |
normal |
| Exploitable |
local |
| Package |
Vulnerable versions |
Unaffected versions |
Architecture(s) |
| app-benchmarks/lmbench |
<=
3 |
|
All supported architectures
|
Related bugreports:
#246015
Synopsis
Multiple insecure temporary file usage issues have been reported in
LMBench, allowing for symlink attacks.
2.
Impact Information
Background
LMBench is a suite of simple, portable benchmarks for UNIX platforms.
Description
Dmitry E. Oboukhov reported that the rccs and STUFF scripts do not
handle "/tmp/sdiff.#####" temporary files securely. NOTE: There might
be further occurances of insecure temporary file usage.
Impact
A local attacker could perform symlink attacks to overwrite arbitrary
files with the privileges of the user running the application.
3.
Resolution Information
Workaround
There is no known workaround at this time.
Resolution
LMBench has been removed from Portage. We recommend that users unmerge
LMBench:
Code Listing 3.1: Resolution |
# emerge --unmerge app-benchmarks/lmbench
|
4.
References
|