HP B6848AB GTK+ Library Insecure File Permissions Vulnerability
BID:10332
Info
HP B6848AB GTK+ Library Insecure File Permissions Vulnerability
| Bugtraq ID: | 10332 |
| Class: | Access Validation Error |
| CVE: | |
| Remote: | No |
| Local: | Yes |
| Published: | May 12 2004 12:00AM |
| Updated: | May 12 2004 12:00AM |
| Credit: | The vendor announced this vulnerability. |
| Vulnerable: |
HP GTK+ Support Library B6848BA (1.4.gm.46) HP GTK+ Support Library B6848BA HP GTK+ Support Library B6848AB |
| Not Vulnerable: | |
Discussion
HP B6848AB GTK+ Library Insecure File Permissions Vulnerability
HP B6848AB GTK+ Support Library may provide for local privilege escalation. The issue is due to weak default permissions that are set on the installation directories and library files during installation.
This vulnerability may be exploited to execute code with elevate privileges.
HP B6848AB GTK+ Support Library may provide for local privilege escalation. The issue is due to weak default permissions that are set on the installation directories and library files during installation.
This vulnerability may be exploited to execute code with elevate privileges.
Exploit / POC
HP B6848AB GTK+ Library Insecure File Permissions Vulnerability
There is no exploit required.
There is no exploit required.
Solution / Fix
HP B6848AB GTK+ Library Insecure File Permissions Vulnerability
Solution:
HP has released an advisory (HPSBUX01034) that outlines instructions on how a customer can address this issue. Further information can be found in the referenced advisory.
Solution:
HP has released an advisory (HPSBUX01034) that outlines instructions on how a customer can address this issue. Further information can be found in the referenced advisory.
References
HP B6848AB GTK+ Library Insecure File Permissions Vulnerability
References:
References: