Re: Insecure temp file creation fix - peer review please

Erwan Legrand <[email protected]> Wed, 06 Oct 2004 12:14:03 +0200
Newsgroups gmane.comp.security.programming
Organization Deny All
Message-ID <[email protected]>
Derek Fountain wrote:

>A few days back I noticed that the /usr/bin/asciiview script from the 
>aalib-1.4.0-275 package in SUSE-9.1 used insecure temp file creation. The 
>exploit is trivial and allows an attacker to cause a victim to overwrite any 
>of the victim's files. I've reported this to SUSE.
>
>The project over at Sourceforge (http://aa-project.sourceforge.net) appears to 
>be dead, having had no update for 3 years. Emails to the two maintainers (at 
>least the email addresses found in the SUSE RPM information) came bouncing 
>back. So I thought I'd fix the bug myself... :) Since the script is small, I 
>can post it here - see below. Perhaps someone with a bit more experience at 
>this sort of thing can have a look at it to see if I've done it properly?
>
>If my fix checks out I'll post it on the Sourceforge project page, although 
>whether anything good will actually become of it is anyone's guess...
>
>  
>
Hi Derek,

your message is quite old, but I could not find any reply to it on the 
list. The way you create the temporary directory will effectively 
prevent against the exploit you describe.

-- 
Erwan Legrand
Information Security Consultant
[email protected]

Tel : +33 (0)1 40 07 47 28
GSM : +33 (0)6 16 60 26 09
Fax : +33 (0)1 40 07 47 27
Deny All - 5, rue Scribe - 75009 Paris - France
www.denyall.com