CVE-2013-2217
published 2013-09-23CVE-2013-2217: cache.py in Suds 0.4, when tempdir is set to None, allows local users to redirect SOAP queries and possibly have other unspecified impact via a symlink attack…
PriorityP47low1.2CVSS 2.0
AVLACHAuNCNIPAN
EPSS
0.56%
42.8th percentile
cache.py in Suds 0.4, when tempdir is set to None, allows local users to redirect SOAP queries and possibly have other unspecified impact via a symlink attack on a cache file with a predictable name in /tmp/suds/.
Affected
11 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | suds | < suds 0.4.1-8 (bookworm) | suds 0.4.1-8 (bookworm) |
| jeff_ortel | suds | — | — |
| jeff_ortel | suds | >= 0 < 0.4.1-8 | 0.4.1-8 |
| jeff_ortel | suds | >= 0 < 0.4.1-8 | 0.4.1-8 |
| jeff_ortel | suds | >= 0 < 0.4.1-8 | 0.4.1-8 |
| jeff_ortel | suds | >= 0 < 0.4.1-8 | 0.4.1-8 |
| jeff_ortel | suds | >= 0 < 1.0.0 | 1.0.0 |
| opensuse | opensuse | — | — |
| opensuse | opensuse | — | — |
| redhat | enterprise_linux | — | — |
| redhat | enterprise_linux | — | — |
CVSS provenance
nvdv2.01.2LOWAV:L/AC:H/Au:N/C:N/I:P/A:N
osv1.2LOW
vendor_debian1.2LOW
vendor_redhat1.2LOW
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
Suds vulnerability
vendor_ubuntu·2013-10-24
CVE-2013-2217 Suds vulnerability
Title: Suds vulnerability
Summary: Suds could be made to overwrite files.
Ralph Loader discovered that Suds incorrectly handled temporary files. A
local attacker could possibly use this issue to overwrite arbitrary files.
In the default installation of Ubuntu, this should be prevented by the Yama
link restrictions.
Instructions: In general, a standard system update will make all the necessary changes.
Red Hat
python-suds: Insecure temporary directory use when initializing file-based URL cache
vendor_redhat·2013-06-27·CVSS 1.2
CVE-2013-2217 [LOW] CWE-377 python-suds: Insecure temporary directory use when initializing file-based URL cache
python-suds: Insecure temporary directory use when initializing file-based URL cache
cache.py in Suds 0.4, when tempdir is set to None, allows local users to redirect SOAP queries and possibly have other unspecified impact via a symlink attack on a cache file with a predictable name in /tmp/suds/.
Statement: This issue affects the version of python-suds as shipped with Red Hat Enterprise Linux 5 and 6. The Red Hat Security Response Team has rated this issue as having low security impact, a future update may address this flaw.
Package: python-suds (Red Hat Enterprise Linux 5) - Will not fix
Package: python-suds (Red Hat Enterprise Linux 6) - Will not fix
Package: python-suds (Red Hat Enterprise Linux 7) - Will not fix
Debian
CVE-2013-2217: suds - cache.py in Suds 0.4, when tempdir is set to None, allows local users to redirec...
vendor_debian·2013·CVSS 1.2
CVE-2013-2217 [LOW] CVE-2013-2217: suds - cache.py in Suds 0.4, when tempdir is set to None, allows local users to redirec...
cache.py in Suds 0.4, when tempdir is set to None, allows local users to redirect SOAP queries and possibly have other unspecified impact via a symlink attack on a cache file with a predictable name in /tmp/suds/.
Scope: local
bookworm: resolved (fixed in 0.4.1-8)
bullseye: resolved (fixed in 0.4.1-8)
forky: resolved (fixed in 0.4.1-8)
sid: resolved (fixed in 0.4.1-8)
trixie: resolved (fixed in 0.4.1-8)
OSV
Improper Link Resolution Before File Access in Suds
osv·2022-05-14
CVE-2013-2217 [MEDIUM] Improper Link Resolution Before File Access in Suds
Improper Link Resolution Before File Access in Suds
cache.py in Suds 0.4, when tempdir is set to None, allows local users to redirect SOAP queries and possibly have other unspecified impact via a symlink attack on a cache file with a predictable name in /tmp/suds/.
GHSA
Improper Link Resolution Before File Access in Suds
ghsa·2022-05-14
CVE-2013-2217 [MEDIUM] CWE-59 Improper Link Resolution Before File Access in Suds
Improper Link Resolution Before File Access in Suds
cache.py in Suds 0.4, when tempdir is set to None, allows local users to redirect SOAP queries and possibly have other unspecified impact via a symlink attack on a cache file with a predictable name in /tmp/suds/.
OSV
CVE-2013-2217: cache
osv·2013-09-23·CVSS 1.2
CVE-2013-2217 [LOW] CVE-2013-2217: cache
cache.py in Suds 0.4, when tempdir is set to None, allows local users to redirect SOAP queries and possibly have other unspecified impact via a symlink attack on a cache file with a predictable name in /tmp/suds/.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2013-2217 python-suds: Insecure temporary directory use when initializing file-based URL cache [epel-all]
bugzilla·2013-06-27·CVSS 1.2
CVE-2013-2217 [LOW] CVE-2013-2217 python-suds: Insecure temporary directory use when initializing file-based URL cache [epel-all]
CVE-2013-2217 python-suds: Insecure temporary directory use when initializing file-based URL cache [epel-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora EPEL.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When creating a Bodhi update request, please use the bodhi submission link
noted in the next comment(s). This will include the bug IDs of this
tracking bug as well as the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
Bodhi notes field when av
Bugzilla
CVE-2013-2217 python-suds: Insecure temporary directory use when initializing file-based URL cache [fedora-all]
bugzilla·2013-06-27·CVSS 1.2
CVE-2013-2217 [LOW] CVE-2013-2217 python-suds: Insecure temporary directory use when initializing file-based URL cache [fedora-all]
CVE-2013-2217 python-suds: Insecure temporary directory use when initializing file-based URL cache [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When creating a Bodhi update request, please use the bodhi submission link
noted in the next comment(s). This will include the bug IDs of this
tracking bug as well as the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
Bodhi notes field when avail
Bugzilla
CVE-2013-2217 python-suds: Insecure temporary directory use when initializing file-based URL cache
bugzilla·2013-06-27·CVSS 1.2
CVE-2013-2217 [LOW] CVE-2013-2217 python-suds: Insecure temporary directory use when initializing file-based URL cache
CVE-2013-2217 python-suds: Insecure temporary directory use when initializing file-based URL cache
python-suds creates and uses some sort of cache in /tmp/suds. It appears to make no attempt to check that the cache is not created or modified by a different user.
After running a SOAP request using suds, I notice the /tmp/suds directory. I chown'd -R /tmp/suds to a different user, and chmod'd -R 777.
Then stracing the script sending soap requests with python-suds, and I see:
stat("/tmp/suds/suds-3359686402328425149-document.px", {st_mode=S_IFREG|0777, open("/tmp/suds/suds-3359686402328425149-document.px", O_RDONLY) = 3
read(3, "\200\2(csuds.sax.document\nDocument\nq"..., 4096) = 4096
[I note that even if python-suds were inspecting the stat result at some later point to check user & per
http://lists.opensuse.org/opensuse-updates/2013-07/msg00062.htmlhttp://www.openwall.com/lists/oss-security/2013/06/27/8http://www.ubuntu.com/usn/USN-2008-1https://bugzilla.redhat.com/show_bug.cgi?id=978696http://lists.opensuse.org/opensuse-updates/2013-07/msg00062.htmlhttp://www.openwall.com/lists/oss-security/2013/06/27/8http://www.ubuntu.com/usn/USN-2008-1https://bugzilla.redhat.com/show_bug.cgi?id=978696
2013-09-23
Published