docs.info.apple.comConfirmation
http://docs.info.apple.com/article.html?artnum=306172 CVE-2004-0996
Cscope 13.0/15.x - Insecure Temporary File Creation (1)
Record summary
CVE-2004-0996 has a selected CVSS score of 2.1; EIP currently links 2 catalogued exploits.
Description
main.c in cscope 15-4 and 15-5 creates temporary files with predictable filenames, which allows local users to overwrite arbitrary files via a symlink attack.
Description source: CVE List
Exploitation context
Available material
- Catalogued exploits
- 2
Proofs of concept
2Catalogued exploits
ExploitDBCscope 13.0/15.x - Insecure Temporary File Creation (1)ExploitDB exploitby GangstuckNot analyzed1 file
ExploitDBCscope 13.0/15.x - Insecure Temporary File Creation (2)ExploitDB exploitby GangstuckNot analyzed1 file
References
Showing 12 of 14APPLE-SA-2007-07-31Vendor advisory
http://lists.apple.com/archives/security-announce//2007/Jul/msg00004.html 20041124 STG Security Advisory: [SSA-20041122-09] cscope insecure temp file creation vulnerabilitymailing list
http://marc.info/?l=bugtraq&m=110133485519690&w=2 26235Third-party advisory
http://secunia.com/advisories/26235 DSA-610Vendor advisory
http://www.debian.org/security/2004/dsa-610 GLSA-200412-11Vendor advisory
http://www.gentoo.org/security/en/glsa/glsa-200412-11.xml 20041117 RX171104 Cscope v15.5 and minors - symlink vulnerability - advisory, exploit and patch.mailing list
http://www.securityfocus.com/archive/1/381443 20041118 Re: RX171104 Cscope v15.5 and minors - symlink vulnerability - advisory, exploit and patch.mailing list
http://www.securityfocus.com/archive/1/381506 20041118 Re: RX171104 Cscope v15.5 and minors - symlink vulnerability - advisory, exploit and patch.mailing list
http://www.securityfocus.com/archive/1/381611 11697vdb entry
http://www.securityfocus.com/bid/11697 25159vdb entry
http://www.securityfocus.com/bid/25159 ADV-2007-2732vdb entry
http://www.vupen.com/english/advisories/2007/2732