Overview
xmcd is an x11/motif CD playing utility, in the public domain. cda, the command line interface to xmcd, executes with system administrator privileges. It is vulnerable to a symbolic link attack that may allow a local user to obtain administrator privileges.
Description
cda, the command line interface to xmcd, executes with system administrator privileges. It creates insecure temporary files with predictable names in /tmp, a world-writable directory. |
Impact
By creating symbolic links with appropriate names, a local attacker may overwrite any writable file on the system. If the attacker can control the content of the overwritten files, elevation of privileges may result. |
Solution
Apply vendor patches; see the Systems Affected section below. |
Remove the setuid protection from cda. |
Vendor Information
CVSS Metrics
Group | Score | Vector |
---|---|---|
Base | ||
Temporal | ||
Environmental |
References
Acknowledgements
This vulnerability was first reported by Paul Starzetz.
This document was last modified by Tim Shimeall.
Other Information
CVE IDs: | CVE-2001-1119 |
Severity Metric: | 9.98 |
Date Public: | 2001-08-23 |
Date First Published: | 2001-11-15 |
Date Last Updated: | 2001-11-15 16:22 UTC |
Document Revision: | 11 |