Gentoo SETI@home EBuild Insecure Default Permissions Vulnerability
BID:11699
Info
Gentoo SETI@home EBuild Insecure Default Permissions Vulnerability
| Bugtraq ID: | 11699 |
| Class: | Configuration Error |
| CVE: | |
| Remote: | No |
| Local: | Yes |
| Published: | Nov 17 2004 12:00AM |
| Updated: | Nov 17 2004 12:00AM |
| Credit: | This issue was disclosed in a Gentoo advisory. |
| Vulnerable: |
Gentoo Linux |
| Not Vulnerable: | |
Discussion
Gentoo SETI@home EBuild Insecure Default Permissions Vulnerability
The Gentoo SETI@home eBuild package is reported prone to a weak default permissions vulnerability.
A local attacker may exploit this vulnerability to escalate privileges.
The Gentoo SETI@home eBuild package is reported prone to a weak default permissions vulnerability.
A local attacker may exploit this vulnerability to escalate privileges.
Exploit / POC
Gentoo SETI@home EBuild Insecure Default Permissions Vulnerability
No exploit is required.
No exploit is required.
Solution / Fix
Gentoo SETI@home EBuild Insecure Default Permissions Vulnerability
Solution:
Gentoo has released an advisory (GLSA 200411-26) to address this and other related issues. Please see the referenced advisory for more information. Gentoo users may carry out the following commands to update their computers:
emerge --sync
emerge --ask --oneshot --verbose ">=app-sci/setiathome-3.08-r4"
Solution:
Gentoo has released an advisory (GLSA 200411-26) to address this and other related issues. Please see the referenced advisory for more information. Gentoo users may carry out the following commands to update their computers:
emerge --sync
emerge --ask --oneshot --verbose ">=app-sci/setiathome-3.08-r4"
References
Gentoo SETI@home EBuild Insecure Default Permissions Vulnerability
References:
References:
- SETI@home Homepage (SETI)