Secunia Logo  
 
GpsDrive Multiple Insecure Temporary Files
Secunia Advisory: SA31694
Release Date: 2008-08-29
Last Update: 2009-01-02
Popularity: 2,247 views

Critical:
Not critical
Impact: Privilege escalation
Where: Local system
Solution Status: Vendor Workaround

Software:GpsDrive 2.x

Subscribe: Instant alerts on relevant vulnerabilities

CVE reference:CVE-2008-4959
CVE-2008-5380
CVE-2008-5703


Description:
Some security issues have been reported in GpsDrive, which can be exploited by malicious, local users to perform certain actions with escalated privileges.

1) The "geo-code" script handles temporary files in an insecure manner.

For more information:
SA31655

2) The "geo-nearest" script handles temporary files in an insecure manner. This can be exploited via symlink attacks to e.g. overwrite arbitrary files with the privileges of the user running the script.

3) The "gpssmswatch" script and the "signalposreq()" function in splash.c handle temporary files in an insecure manner. This can be exploited via symlink attacks to e.g. overwrite arbitrary files with the privileges of the user running the script or application.

Solution:
Fixed in the SVN repository.

Provided and/or discovered by:
1, 2) Reported by Dmitry E. Oboukhov in a Debian bug report.
3) Raphael Geissert

Changelog:
2008-11-07: Added CVE reference.
2008-12-12: Added vulnerability #2 and CVE reference. Updated the "Original Advisory" section.
2008-12-30: Added vulnerability #3. Updated "Solution" section. Updated "Original Advisory" section.
2009-01-02: Added CVE reference.

Original Advisory:
1) http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=496436
2) http://lists.debian.org/debian-devel/2008/08/msg00285.html
3) http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=508597

Other References:
SA31655:
http://secunia.com/advisories/31655/


Track this Secunia Advisory
Customers of the Secunia Vulnerability Intelligence solutions will automatically receive updates when new information regarding this advisory is released.

Read more about our Vulnerability Intelligence solutions and what they can do for you and your company.

About this Secunia Advisory
Please note: The information that this Secunia Advisory is based on comes from a third party unless stated otherwise.

Secunia collects, validates, and verifies all vulnerability reports issued by security research groups, vendors, and others.
  
Latest Advisories

6th Jan, 2009
New advisories: 9
New vulnerabilities: 13
Updated advisories: 21

Moderately // 319 views
PHPAuctions Multiple Vulnerabilities
Moderately // 335 views
Ubuntu update for xterm
Less // 344 views
Ubuntu update for samba

5th Jan, 2009
New advisories: 15
New vulnerabilities: 33
Updated advisories: 64

Moderately // 617 views
NPDS Multiple Vulnerabilities

Solutions | More...  


Send Feedback to Secunia
If you have new information regarding this Secunia advisory or a product in our database, please send it to us using either our web form or email us at vuln@secunia.com.

Ideas, suggestions, and other feedback are most welcome.

Most Popular - 3 Hours

1. YACS "context[path_to_root]" File Inclusion Vulnerabilities // 106 views
2. FrontAccounting "path_to_root" File Inclusion // 101 views
3. Sun Solaris NFS Local Denial of Service Vulnerability // 68 views
4. VMware "vmware-authd" Denial of Service Vulnerability // 68 views
5. Nokia Phones SMS Denial of Service Vulnerability // 67 views
6. STPHPLib Multiple File Inclusion Vulnerabilities // 47 views
7. PHPAuctions Multiple Vulnerabilities // 47 views
8. Ubuntu update for samba // 45 views
9. Php Blue Dragon CMS activecontent.php File Inclusion // 44 views
10. Php Blue Dragon CMS Multiple Vulnerabilities // 42 views