Title: Netscape Communicator /tmp Symlink Vulnerability
Severity: LOW
Description:
Netscape Communicator version 4.73 and prior may be susceptible to a /tmp file race condition when importing certificates. Netscape creates a /tmp file which is world readable and writable in /tmp, without calling stat() or fstat() on the file. As such, it is possible, should a user be able to predict the file name, to cause a symbolic link to be created, and followed elsewhere on the file system.
Additionally, as the file is created mode 666 prior to being fchmod()'d to 600, there may be a window of opportunity for altering the contents of this file.
This issue has only been demonstrated on the Linux binary, for glibc. The sparc Solaris binary does not behave this way.
Affected Products:
- Netscape Communicator 4.5.0
- Netscape Communicator 4.51.0
- Netscape Communicator 4.6.0
- Netscape Communicator 4.61.0
- Netscape Communicator 4.7.0
- Netscape Communicator 4.72.0
- Netscape Communicator 4.73.0
Juniper Networks provides this content via a wide variety of sources and production methods. If notified of errors or omissions in the content of this page, Juniper Networks, at its discretion, will modify or remove the page or leave the content as is, depending on various factors including but not limited to the reputation and authority of the party providing the notification. Please use the contact information displayed elsewhere on this page to report any errors or omissions regarding the content on this page.