W-Channel TC-IDE Embedded Linux Local Privilege Escalation Vulnerabilities
BID:11718
Info
W-Channel TC-IDE Embedded Linux Local Privilege Escalation Vulnerabilities
| Bugtraq ID: | 11718 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | No |
| Local: | Yes |
| Published: | Nov 20 2004 12:00AM |
| Updated: | Nov 20 2004 12:00AM |
| Credit: | This issue was discovered by ECL Security R&D. |
| Vulnerable: |
W-Channel TC-IDE 1.53 W-Channel TC-IDE 1.52 W-Channel TC-IDE 1.51 W-Channel TC-IDE 1.50 |
| Not Vulnerable: |
W-Channel TC-IDE 1.54 |
Discussion
W-Channel TC-IDE Embedded Linux Local Privilege Escalation Vulnerabilities
Multiple local privilege escalation vulnerabilities reportedly exist in W-Channel TC-IDE. These issues are due to input handling errors that allow a local attacker to start applications with escalated privileges.
A local attacker may leverage these issues to gain superuser access to the affected computer, facilitating privilege escalation.
Multiple local privilege escalation vulnerabilities reportedly exist in W-Channel TC-IDE. These issues are due to input handling errors that allow a local attacker to start applications with escalated privileges.
A local attacker may leverage these issues to gain superuser access to the affected computer, facilitating privilege escalation.
Exploit / POC
W-Channel TC-IDE Embedded Linux Local Privilege Escalation Vulnerabilities
No exploit is required to leverage any of these issues.
No exploit is required to leverage any of these issues.
Solution / Fix
W-Channel TC-IDE Embedded Linux Local Privilege Escalation Vulnerabilities
Solution:
The vendor has released an upgrade that deals with these issues. Users should contact the vendor for information on obtaining the fix.
Solution:
The vendor has released an upgrade that deals with these issues. Users should contact the vendor for information on obtaining the fix.
References
W-Channel TC-IDE Embedded Linux Local Privilege Escalation Vulnerabilities
References:
References:
- TC-IDE Home Page (W-Channel)
- [ECL] WCI TC-IDE embedded linux vulnerabilities (ECL team
)