vendor:
BRU Backup Software
by:
Andrew Griffiths (nullptr@tasmail.com)
4.6
CVSS
MEDIUM
Symbolic Link Attack
59
CWE
Product Name: BRU Backup Software
Affected Version From:
Affected Version To:
Patch Exists: NO
Related CWE:
CPE: a:tolis_group:bru_backup_software
Platforms Tested: UNIX, Linux
BRU Backup Software Insecure Temporary File Creation
The BRU backup software creates temporary files insecurely by using easily predicted temporary filenames in the /tmp/brutest.$$ format. This vulnerability allows a local user to launch a symbolic link attack, potentially leading to the overwriting of system files or elevated privileges.
Mitigation:
The vendor should update the BRU backup software to securely create temporary files and check for the existence of files with the same name before creating new ones. Users should ensure that the software is updated to the latest version.