PT-2009-1031 · Debian+1 · Debian+1

James Stone

·

Published

2009-04-09

·

Updated

2009-04-16

·

CVE-2009-1253

CVSS v2.0

6.8

Medium

VectorAV:N/AC:M/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions Tunapie version 2.1 Tunapie (affected versions not specified) in Debian GNU/Linux
Description The issue allows local users to overwrite arbitrary files via a symlink attack on an unspecified temporary file. Additionally, there are multiple vulnerabilities in the Tunapie package of the Debian GNU/Linux operating system that can be exploited remotely, potentially leading to breaches of confidentiality, integrity, and availability of protected information.
Recommendations For Tunapie version 2.1, consider restricting access to temporary files to prevent symlink attacks until a patch is available. For Tunapie in Debian GNU/Linux, restrict remote access to the Tunapie package to minimize the risk of exploitation. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Link Following

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2015-03455
CVE-2009-1253
DSA-1764-1

Affected Products

Debian
Tunapie