ID

VAR-201005-0115


CVE

CVE-2010-1438


TITLE

WAFP Service disruption in (DoS) Vulnerability such as

Trust: 0.8

sources: JVNDB: JVNDB-2010-004669

DESCRIPTION

Web Application Finger Printer (WAFP) 0.01-26c3 uses fixed pathnames under /tmp for temporary files and directories, which (1) allows local users to cause a denial of service (application outage) by creating a file with a pathname that the product expects is available for its own internal use, (2) allows local users to overwrite arbitrary files via symlink attacks on certain files in /tmp, (3) might allow local users to delete arbitrary files and directories via a symlink attack on a directory under /tmp, and (4) might make it easier for local users to obtain sensitive information by reading files in a directory under /tmp, related to (a) lib/wafp_pidify.rb, (b) utils/generate_wafp_fingerprint.sh, (c) utils/online_update.sh, and (d) utils/extract_from_db.sh. An attacker with local access could potentially exploit this issue to perform symbolic-link attacks, overwriting arbitrary files in the context of the affected application. Successfully mounting a symlink attack may allow the attacker to delete or corrupt sensitive files, which may result in a denial of service. Other attacks may also be possible

Trust: 1.98

sources: NVD: CVE-2010-1438 // JVNDB: JVNDB-2010-004669 // BID: 39760 // VULHUB: VHN-44043

AFFECTED PRODUCTS

vendor:myttymodel:webapplication finger printerscope:eqversion:0.01-26c3

Trust: 1.8

vendor:wafpmodel:0.01-26c3scope: - version: -

Trust: 0.3

sources: BID: 39760 // JVNDB: JVNDB-2010-004669 // NVD: CVE-2010-1438

CVSS

SEVERITY

CVSSV2

CVSSV3

nvd@nist.gov: CVE-2010-1438
value: MEDIUM

Trust: 1.0

NVD: CVE-2010-1438
value: MEDIUM

Trust: 0.8

CNNVD: CNNVD-201005-059
value: MEDIUM

Trust: 0.6

VULHUB: VHN-44043
value: MEDIUM

Trust: 0.1

nvd@nist.gov: CVE-2010-1438
severity: MEDIUM
baseScore: 4.4
vectorString: AV:L/AC:M/AU:N/C:P/I:P/A:P
accessVector: LOCAL
accessComplexity: MEDIUM
authentication: NONE
confidentialityImpact: PARTIAL
integrityImpact: PARTIAL
availabilityImpact: PARTIAL
exploitabilityScore: 3.4
impactScore: 6.4
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 1.8

VULHUB: VHN-44043
severity: MEDIUM
baseScore: 4.4
vectorString: AV:L/AC:M/AU:N/C:P/I:P/A:P
accessVector: LOCAL
accessComplexity: MEDIUM
authentication: NONE
confidentialityImpact: PARTIAL
integrityImpact: PARTIAL
availabilityImpact: PARTIAL
exploitabilityScore: 3.4
impactScore: 6.4
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 0.1

sources: VULHUB: VHN-44043 // JVNDB: JVNDB-2010-004669 // CNNVD: CNNVD-201005-059 // NVD: CVE-2010-1438

PROBLEMTYPE DATA

problemtype:NVD-CWE-Other

Trust: 1.0

problemtype:CWE-Other

Trust: 0.8

sources: JVNDB: JVNDB-2010-004669 // NVD: CVE-2010-1438

THREAT TYPE

local

Trust: 0.9

sources: BID: 39760 // CNNVD: CNNVD-201005-059

TYPE

other

Trust: 0.6

sources: CNNVD: CNNVD-201005-059

CONFIGURATIONS

sources: JVNDB: JVNDB-2010-004669

PATCH

title:webapplicationfingerprinterurl:http://code.google.com/p/webapplicationfingerprinter/

Trust: 0.8

sources: JVNDB: JVNDB-2010-004669

EXTERNAL IDS

db:NVDid:CVE-2010-1438

Trust: 2.8

db:BIDid:39760

Trust: 2.0

db:OPENWALLid:OSS-SECURITY/2010/04/28/3

Trust: 1.7

db:OPENWALLid:OSS-SECURITY/2010/04/27/6

Trust: 1.7

db:JVNDBid:JVNDB-2010-004669

Trust: 0.8

db:MLISTid:[OSS-SECURITY] 20100427 RE: WAFP INSECURE TEMPORARY DIRECTORY

Trust: 0.6

db:MLISTid:[OSS-SECURITY] 20100427 WAFP INSECURE TEMPORARY DIRECTORY

Trust: 0.6

db:CNNVDid:CNNVD-201005-059

Trust: 0.6

db:VULHUBid:VHN-44043

Trust: 0.1

sources: VULHUB: VHN-44043 // BID: 39760 // JVNDB: JVNDB-2010-004669 // CNNVD: CNNVD-201005-059 // NVD: CVE-2010-1438

REFERENCES

url:http://code.google.com/p/webapplicationfingerprinter/issues/detail?id=8

Trust: 2.0

url:http://www.securityfocus.com/bid/39760

Trust: 1.7

url:http://www.openwall.com/lists/oss-security/2010/04/28/3

Trust: 1.7

url:http://www.openwall.com/lists/oss-security/2010/04/27/6

Trust: 1.7

url:http://cve.mitre.org/cgi-bin/cvename.cgi?name=cve-2010-1438

Trust: 0.8

url:http://web.nvd.nist.gov/view/vuln/detail?vulnid=cve-2010-1438

Trust: 0.8

url:http://mytty.org/wafp/

Trust: 0.3

url:http://permalink.gmane.org/gmane.comp.security.oss.general/2853

Trust: 0.3

sources: VULHUB: VHN-44043 // BID: 39760 // JVNDB: JVNDB-2010-004669 // CNNVD: CNNVD-201005-059 // NVD: CVE-2010-1438

CREDITS

Henri Salo

Trust: 0.3

sources: BID: 39760

SOURCES

db:VULHUBid:VHN-44043
db:BIDid:39760
db:JVNDBid:JVNDB-2010-004669
db:CNNVDid:CNNVD-201005-059
db:NVDid:CVE-2010-1438

LAST UPDATE DATE

2025-04-11T23:19:06.375000+00:00


SOURCES UPDATE DATE

db:VULHUBid:VHN-44043date:2010-05-11T00:00:00
db:BIDid:39760date:2010-04-28T00:00:00
db:JVNDBid:JVNDB-2010-004669date:2012-09-25T00:00:00
db:CNNVDid:CNNVD-201005-059date:2021-12-06T00:00:00
db:NVDid:CVE-2010-1438date:2025-04-11T00:51:21.963

SOURCES RELEASE DATE

db:VULHUBid:VHN-44043date:2010-05-06T00:00:00
db:BIDid:39760date:2010-04-28T00:00:00
db:JVNDBid:JVNDB-2010-004669date:2012-09-25T00:00:00
db:CNNVDid:CNNVD-201005-059date:2010-04-28T00:00:00
db:NVDid:CVE-2010-1438date:2010-05-06T14:53:01.390