SATAN rex.satan /tmp/rex.$$ Symlink Arbitrary File Overwrite
Local Access Required
Loss of Integrity
SATAN contains a flaw that allows local attackers to overwrite arbitrary files and possibly gain root priveleges. The flaw is due to a lack of sanity checking on calls to temporary files created in /tmp by bin/rex.satan that does not check for existing files with the same name. Such flaws can be taken advantage of with symlinks and arbitrary files can be overwritten or appended to.
Due to the fact SATAN has not been upgraded and the last version available is still vulnerable, administrators should use other freeware alternatives such as SAINT.