Gentoo Net-SNMP Local Privilege Escalation Vulnerability
BID:14745
Info
Gentoo Net-SNMP Local Privilege Escalation Vulnerability
| Bugtraq ID: | 14745 |
| Class: | Design Error |
| CVE: | |
| Remote: | No |
| Local: | Yes |
| Published: | Sep 06 2005 12:00AM |
| Updated: | Sep 06 2005 12:00AM |
| Credit: | Discovery is credited to James Cloos. |
| Vulnerable: |
Gentoo net-analyzer/net-snmp 5.2.1 .2 Gentoo net-analyzer/net-snmp 5.2.1 -r1 |
| Not Vulnerable: |
Gentoo net-analyzer/net-snmp 5.2.1 .2-r1 |
Discussion
Gentoo Net-SNMP Local Privilege Escalation Vulnerability
Gentoo Net-SNMP is affected by a local privilege escalation vulnerability.
A local attacker with portage group privileges may create a shared object that would be loaded by Net-SNMP Perl modules, potentially resulting in arbitrary code execution in the context of the user running the Perl script.
Gentoo Net-SNMP versions prior to 5.2.1.2-r1 are affected by this vulnerability. This issue does not affect the Net-SNMP suite.
Gentoo Net-SNMP is affected by a local privilege escalation vulnerability.
A local attacker with portage group privileges may create a shared object that would be loaded by Net-SNMP Perl modules, potentially resulting in arbitrary code execution in the context of the user running the Perl script.
Gentoo Net-SNMP versions prior to 5.2.1.2-r1 are affected by this vulnerability. This issue does not affect the Net-SNMP suite.
Exploit / POC
Gentoo Net-SNMP Local Privilege Escalation Vulnerability
An exploit is not required.
An exploit is not required.
Solution / Fix
Gentoo Net-SNMP Local Privilege Escalation Vulnerability
Solution:
Gentoo has released advisory GLSA 200509-05 to address this issue. Please see the referenced advisory for more information. Gentoo users may upgrade by carrying out the following commands:
emerge --sync
emerge --ask --oneshot --verbose ">=net-analyzer/net-snmp-5.2.1.2-r1"
Solution:
Gentoo has released advisory GLSA 200509-05 to address this issue. Please see the referenced advisory for more information. Gentoo users may upgrade by carrying out the following commands:
emerge --sync
emerge --ask --oneshot --verbose ">=net-analyzer/net-snmp-5.2.1.2-r1"
References
Gentoo Net-SNMP Local Privilege Escalation Vulnerability
References:
References: