Gentoo Linux XnView Insecure RPATH Vulnerability
BID:16087
Info
Gentoo Linux XnView Insecure RPATH Vulnerability
| Bugtraq ID: | 16087 |
| Class: | Design Error |
| CVE: | |
| Remote: | No |
| Local: | Yes |
| Published: | Dec 30 2005 12:00AM |
| Updated: | Dec 30 2005 12:00AM |
| Credit: | Discovered by nelchael. |
| Vulnerable: |
Gentoo x11-misc/xnview |
| Not Vulnerable: |
Gentoo x11-misc/xnview 1.70 -r1 |
Discussion
Gentoo Linux XnView Insecure RPATH Vulnerability
Gentoo Linux XnView is susceptible to an insecure RPATH vulnerability.
This issue may allow local attackers to execute code with the privileges of a user that executes the application.
Gentoo Linux XnView versions prior to 1.70-r1 are vulnerable to this issue.
Gentoo Linux XnView is susceptible to an insecure RPATH vulnerability.
This issue may allow local attackers to execute code with the privileges of a user that executes the application.
Gentoo Linux XnView versions prior to 1.70-r1 are vulnerable to this issue.
Exploit / POC
Gentoo Linux XnView Insecure RPATH Vulnerability
An exploit is not required.
An exploit is not required.
Solution / Fix
Gentoo Linux XnView Insecure RPATH Vulnerability
Solution:
Gentoo has released advisory GLSA 200510-14, along with fixes to address this issue. Users of affected packages are urged to execute the following commands with superuser privileges:
emerge --sync
emerge --ask --oneshot --verbose ">=x11-misc/xnview-1.70-r1"
System administrators may use the chrpath utility to remove the DT_RPATH field from the XnView utilities by carrying out the following commands:
emerge app-admin/chrpath
chrpath --delete /opt/bin/nconvert /opt/bin/nview /opt/bin/xnview
Solution:
Gentoo has released advisory GLSA 200510-14, along with fixes to address this issue. Users of affected packages are urged to execute the following commands with superuser privileges:
emerge --sync
emerge --ask --oneshot --verbose ">=x11-misc/xnview-1.70-r1"
System administrators may use the chrpath utility to remove the DT_RPATH field from the XnView utilities by carrying out the following commands:
emerge app-admin/chrpath
chrpath --delete /opt/bin/nconvert /opt/bin/nview /opt/bin/xnview
References
Gentoo Linux XnView Insecure RPATH Vulnerability
References:
References: