Cheetah Local Privilege Escalation Vulnerability
BID:13662
Info
Cheetah Local Privilege Escalation Vulnerability
| Bugtraq ID: | 13662 |
| Class: | Design Error |
| CVE: | |
| Remote: | No |
| Local: | Yes |
| Published: | May 17 2005 12:00AM |
| Updated: | May 17 2005 12:00AM |
| Credit: | Discovery is credited to Brian Bird. |
| Vulnerable: |
Gentoo Linux Cheetah Cheetah 0.9.16 a1 |
| Not Vulnerable: |
Cheetah Cheetah 0.9.17 rc1 |
Discussion
Cheetah Local Privilege Escalation Vulnerability
Cheetah is prone to a local privilege escalation vulnerability.
The issue arises because the application imports modules from the '/tmp' directory before searching for the path from the 'PYTHONPATH' variable.
This can result in arbitrary code execution granting elevated privileges to an attacker.
Cheetah versions prior to 0.9.17-rc1 are affected by this issue.
Cheetah is prone to a local privilege escalation vulnerability.
The issue arises because the application imports modules from the '/tmp' directory before searching for the path from the 'PYTHONPATH' variable.
This can result in arbitrary code execution granting elevated privileges to an attacker.
Cheetah versions prior to 0.9.17-rc1 are affected by this issue.
Exploit / POC
Cheetah Local Privilege Escalation Vulnerability
An exploit is not required.
An exploit is not required.
Solution / Fix
Cheetah Local Privilege Escalation Vulnerability
Solution:
The vendor has released Cheetah 0.9.17rc1 to address this issue.
Gentoo has released advisory GLSA 200505-14 to address this issue. Please see the referenced advisory for more information. Gentoo users may carry out the following commands to update their computers:
emerge --sync
emerge --ask --oneshot --verbose ">=dev-python/cheetah-0.9.17-rc1"
Cheetah Cheetah 0.9.16 a1
Solution:
The vendor has released Cheetah 0.9.17rc1 to address this issue.
Gentoo has released advisory GLSA 200505-14 to address this issue. Please see the referenced advisory for more information. Gentoo users may carry out the following commands to update their computers:
emerge --sync
emerge --ask --oneshot --verbose ">=dev-python/cheetah-0.9.17-rc1"
Cheetah Cheetah 0.9.16 a1
-
Cheetah Cheetah-0.9.17rc1.tar.gz
http://prdownloads.sourceforge.net/cheetahtemplate/Cheetah-0.9.17rc1.t ar.gz?download
References
Cheetah Local Privilege Escalation Vulnerability
References:
References:
- Cheetah Home Page (Cheetah)
- Security hole in Cheetah? (Brian Bird
)