search menu icon-carat-right cmu-wordmark

CERT Coordination Center

sort creates temporary files insecurely

Vulnerability Note VU#417216

Original Release Date: 2001-08-20 | Last Revised: 2003-05-29

Overview

The sort utility creates temporary files insecurely, making sort subject to a denial-of-service attack.

Description

The UNIX sort utility creates temporary files with predictable names. The creation is done in a manner to prevent information loss via a symlink attack, but existence of the file will cause sort to fail, as it aborts when the creation fails.

Impact

By crashing the sort utility, an intruder may be able to block the operation of system administration programs.

Solution

Apply vendor patches; see the Systems Affected section below.

Vendor Information

417216
 

View all 22 vendors View less vendors


CVSS Metrics

Group Score Vector
Base
Temporal
Environmental

References

Acknowledgements

This vulnerability was identified by FreeBSD.

This document was last modified by Tim Shimeall.

Other Information

CVE IDs: CVE-2001-0310
Severity Metric: 0.84
Date Public: 2001-01-30
Date First Published: 2001-08-20
Date Last Updated: 2003-05-29 18:48 UTC
Document Revision: 14

Sponsored by CISA.