CVE-2013-3368: Low severity best practical solutions request tracker vulnerability
Published Aug 23, 2013
·Updated
bin/rt in Request Tracker (RT) 3.8.x before 3.8.17 and 4.0.x before 4.0.13 allows local users to overwrite arbitrary files via a symlink attack on a temporary file with predictable name.
Affected Software
77 affected components
bestpractical RT=4.0.0
bestpractical RT=4.0.0-rc1
bestpractical RT=4.0.0-rc2
bestpractical RT=4.0.0-rc3
bestpractical RT=4.0.0-rc4
bestpractical RT=4.0.0-rc5
bestpractical RT=4.0.0-rc6
bestpractical RT=4.0.0-rc7
bestpractical RT=4.0.0-rc8
bestpractical RT=4.0.1
bestpractical RT=4.0.1-rc1
bestpractical RT=4.0.1-rc2
bestpractical RT=4.0.2
bestpractical RT=4.0.2-rc1
bestpractical RT=4.0.2-rc2
bestpractical RT=4.0.3
bestpractical RT=4.0.3-rc1
bestpractical RT=4.0.3-rc2
bestpractical RT=4.0.4
bestpractical RT=4.0.5
bestpractical RT=4.0.5-rc1
bestpractical RT=4.0.6
bestpractical RT=4.0.7
bestpractical RT=4.0.7-rc1
bestpractical RT=4.0.8
bestpractical RT=4.0.8-rc1
bestpractical RT=4.0.8-rc2
bestpractical RT=4.0.9
bestpractical RT=4.0.10
bestpractical RT=4.0.11
bestpractical RT=4.0.12
bestpractical RT=3.8.0
bestpractical RT=3.8.0-preflight1
bestpractical RT=3.8.0-rc1
bestpractical RT=3.8.0-rc2
bestpractical RT=3.8.0-rc3
bestpractical RT=3.8.1
bestpractical RT=3.8.1-preflight0
bestpractical RT=3.8.1-rc1
bestpractical RT=3.8.1-rc2
bestpractical RT=3.8.1-rc3
bestpractical RT=3.8.1-rc4
bestpractical RT=3.8.1-rc5
bestpractical RT=3.8.2
bestpractical RT=3.8.2-rc1
bestpractical RT=3.8.2-rc2
bestpractical RT=3.8.3
bestpractical RT=3.8.3-rc1
bestpractical RT=3.8.3-rc2
bestpractical RT=3.8.4
bestpractical RT=3.8.4-rc1
bestpractical RT=3.8.5
bestpractical RT=3.8.6
bestpractical RT=3.8.6-rc1
bestpractical RT=3.8.7
bestpractical RT=3.8.7-rc1
bestpractical RT=3.8.8
bestpractical RT=3.8.8-rc2
bestpractical RT=3.8.8-rc3
bestpractical RT=3.8.8-rc4
bestpractical RT=3.8.9
bestpractical RT=3.8.9-rc1
bestpractical RT=3.8.9-rc2
bestpractical RT=3.8.9-rc3
bestpractical RT=3.8.10
bestpractical RT=3.8.10-rc1
bestpractical RT=3.8.11
bestpractical RT=3.8.11-rc1
bestpractical RT=3.8.11-rc2
bestpractical RT=3.8.12
bestpractical RT=3.8.13
bestpractical RT=3.8.13-rc1
bestpractical RT=3.8.13-rc2
bestpractical RT=3.8.14
bestpractical RT=3.8.14-rc1
bestpractical RT=3.8.15
bestpractical RT=3.8.16
Remediation
Event History
Aug 23, 2013
CVE Published
via MITRE·04:00 PM
Data Sourced
via MITRE·04:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2013-3368?
CVE-2013-3368 has a medium severity level due to the potential for local users to overwrite arbitrary files.
2
How do I fix CVE-2013-3368?
To fix CVE-2013-3368, upgrade your Request Tracker to version 3.8.17 or 4.0.13 or later.
3
What types of systems are affected by CVE-2013-3368?
CVE-2013-3368 affects installations of Request Tracker versions 3.8.x before 3.8.17 and 4.0.x before 4.0.13.
4
What is a symlink attack in the context of CVE-2013-3368?
A symlink attack in CVE-2013-3368 allows local users to exploit predictable temporary file names to overwrite files.
5
Who can exploit CVE-2013-3368?
Local users on systems running vulnerable versions of Request Tracker can exploit CVE-2013-3368.