getipacctg in rancid 2.3.2~a8 allows local users to overwrite arbitrary files via a symlink attack on (1) /tmp/ipacct.#####.prefixes, (2) /tmp/ipacct.#####.sorted, (3) /tmp/ipacct.#####.pl, and (4) /tmp/ipacct.##### temporary files.
The product attempts to access a file based on the filename, but it does not properly prevent that filename from identifying a link or shortcut that resolves to an unintended resource.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Rancid | Shrubbery | 2.3.2~a8 (including) | 2.3.2~a8 (including) |
Rancid | Ubuntu | dapper | * |
Rancid | Ubuntu | gutsy | * |
Rancid | Ubuntu | hardy | * |
Rancid | Ubuntu | intrepid | * |
Rancid | Ubuntu | upstream | * |