about advertise contact
Search: Home Vulnerabilities Exploits News Articles RSS Feeds Archive Talk

exploits , vulnerabilities , articles , MacOSXLabs RsyncX Insecure Temporary File Creation Vulnerability


Title MacOSXLabs RsyncX Insecure Temporary File Creation Vulnerability
Published 2004-09-17-12:00AM
Updated 2004-09-17-05:27PM
Class Design Error
CVE   CVE-MAP-NOMATCH
Remote  No
Local  Yes
Credit  Discovery of this vulnerability is credited to Matt Johnston <matt@ucc.asn.au>.
Vulnerable  MacOSXLabs RsyncX 2.1
Not Vulnerable  
Code   The following example is available:

When using the scheduler component of RsyncX, /tmp/cron_rsyncxtmp
is insecurely used. A user can create a dir /tmp/blahdir,
then
ln -s /tmp/blahdir/file /tmp/cron.rsyncxtmp

After RsyncX scheduler is used by an admin, /etc/crontab
will become a symlink pointing to /tmp/blahdir/file.
TXT  t3xt 1t!


Advertising

Copyright 2007, SecurityDot
Tue, 02 Dec 2008 05:04:35 +0000

Friends : milw0rm.com , secunia.com , securityfocus.com
GOOGLE
NEWS EXPLOITS VULNS
exploits , 0day exploits , newest exploits , vulnerabilities , newest vulnerabilities , 0day vulnerabilities , newest articles , linux articles , articles
Sexdokhtar pussyinpak IceWarp We \n Crack Data YaBB Se Wetteens.c gillian an CMS is Fre FOR thrisha ga XLXXSEX CMS is Fre blue flim Apache htt movie.520q Madhuripho XP Book donload of News Searc news for c Nero-6.6.1 Panas www.nguyen www.bangla Daddy yank OpenSSH 3. news for c MODx Www.Xxx.Co news for c 2.6.5 loca grsec naruto xxx sex imajes 200 /compo www.malaya apache htt t429t pdshoppro j.lo zyxel 660 video noel www.neyant news for C sex school An attack BIGDICKS.C www. sexy. MODx