Lucene search

K
freebsdFreeBSD48A59C96-9C6E-11D9-A040-000A95BC6FAE
HistoryMar 13, 2005 - 12:00 a.m.

wine -- information disclosure due to insecure temporary file handling

2005-03-1300:00:00
vuxml.freebsd.org
5

2.1 Low

CVSS2

Attack Vector

LOCAL

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

NONE

Availability Impact

NONE

AV:L/AC:L/Au:N/C:P/I:N/A:N

0.0004 Low

EPSS

Percentile

5.1%

Due to insecure temporary file creation in the Wine Windows
emulator, it is possible for any user to read potentially
sensitive information from temporary registry files.

When a Win32 application is launched by wine, wine makes
a dump of the Windows registry in /tmp with name
regxxxxyyyy.tmp , where xxxxxx is the pid in hexadecimal
value of the current wine process and yyyy is an integer
value usually equal to zero.
regxxxxyyyy.tmp is created with 0644 (-rw-r–r–)
permissions. This could represent a security problem in a
multi-user environment. Indeed, any local user could
access to windows regstry’s dump and get sensitive
information, like passwords and other private data.

OSVersionArchitecturePackageVersionFilename
FreeBSDanynoarchwine< 20050310UNKNOWN

2.1 Low

CVSS2

Attack Vector

LOCAL

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

NONE

Availability Impact

NONE

AV:L/AC:L/Au:N/C:P/I:N/A:N

0.0004 Low

EPSS

Percentile

5.1%

Related for 48A59C96-9C6E-11D9-A040-000A95BC6FAE