CVE-2014-1639: Low severity Debian Syncevolution vulnerability
syncevo/installcheck-local.sh in syncevolution before 1.3.99.7 uses mktemp to create a safe temporary file but appends a suffix to the original filename and writes to this new filename, which allows local users to overwrite arbitrary files via a symlink attack on the new filename.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
syncevolution/syncevo/installcheck-local.shto a version that resolves this vulnerability.Fixed in 1.3.99.7
Event History
Frequently Asked Questions
What is the severity of CVE-2014-1639?
CVE-2014-1639 is categorized as a high severity vulnerability due to its potential for local users to exploit symlink attacks.
How do I fix CVE-2014-1639?
To fix CVE-2014-1639, upgrade Syncevolution to version 1.3.99.7 or later to mitigate the file overwriting risks.
Who is affected by CVE-2014-1639?
CVE-2014-1639 affects users of Syncevolution versions up to and including 1.3.99.6 on Debian systems.
What types of attacks can exploit CVE-2014-1639?
CVE-2014-1639 can be exploited through a symlink attack, allowing local users to overwrite arbitrary files.
What software is vulnerable in CVE-2014-1639?
The vulnerable software is Syncevolution versions prior to 1.3.99.7, specifically on Debian systems.