vendor:
xNBD
by:
SecurityFocus
7,2
CVSS
HIGH
Insecure Temporary File Handling
36
CWE
Product Name: xNBD
Affected Version From: N/A
Affected Version To: N/A
Patch Exists: No
Related CWE: N/A
CPE: N/A
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: N/A
2013
xNBD Insecure Temporary File Handling
xNBD is prone to a vulnerability because it handles temporary files in an insecure manner. Local attackers may leverage this issue to perform symbolic-link attacks in the context of the affected application. Other attacks may also be possible. An attacker can create a symbolic link to a file they wish to overwrite, and then start the xNBD server. The server will then write to the file pointed to by the symbolic link, allowing the attacker to overwrite the file.
Mitigation:
Ensure that temporary files are handled securely.