PT-2009-1031 · Debian+1 · Debian+1
James Stone
·
Published
2009-04-09
·
Updated
2009-04-16
·
CVE-2009-1253
CVSS v2.0
6.8
Medium
| Vector | AV:N/AC:M/Au:N/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
Tunapie version 2.1
Tunapie (affected versions not specified) in Debian GNU/Linux
Description
The issue allows local users to overwrite arbitrary files via a symlink attack on an unspecified temporary file. Additionally, there are multiple vulnerabilities in the Tunapie package of the Debian GNU/Linux operating system that can be exploited remotely, potentially leading to breaches of confidentiality, integrity, and availability of protected information.
Recommendations
For Tunapie version 2.1, consider restricting access to temporary files to prevent symlink attacks until a patch is available.
For Tunapie in Debian GNU/Linux, restrict remote access to the Tunapie package to minimize the risk of exploitation.
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Link Following
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Debian
Tunapie