Gentoo Pinentry Local Privilege Escalation Vulnerability
BID:16120
Info
Gentoo Pinentry Local Privilege Escalation Vulnerability
| Bugtraq ID: | 16120 |
| Class: | Design Error |
| CVE: | |
| Remote: | No |
| Local: | Yes |
| Published: | Jan 03 2006 12:00AM |
| Updated: | Jan 03 2006 12:00AM |
| Credit: | Discovered by Tavis Ormandy. |
| Vulnerable: |
Gentoo Linux Gentoo app-crypt/pinentry 0.7.2 -r1 Gentoo app-crypt/pinentry 0.7.2 |
| Not Vulnerable: |
Gentoo app-crypt/pinentry 0.7.2 -r2 |
Discussion
Gentoo Pinentry Local Privilege Escalation Vulnerability
pinentry is prone to a local privilege escalation vulnerability.
Successful exploitation can allow a pinentry user to read or write arbitrary files with the privileges of group ID 0.
pinentry is prone to a local privilege escalation vulnerability.
Successful exploitation can allow a pinentry user to read or write arbitrary files with the privileges of group ID 0.
Exploit / POC
Gentoo Pinentry Local Privilege Escalation Vulnerability
An exploit is not required.
An exploit is not required.
Solution / Fix
Gentoo Pinentry Local Privilege Escalation Vulnerability
Solution:
Gentoo has released advisory GLSA 200601-01 and an updated eBuild to address this issue. Users may apply this update by executing the following commands as a superuser:
emerge --sync
emerge --ask --oneshot --verbose ">=app-crypt/pinentry-0.7.2-r2"
Solution:
Gentoo has released advisory GLSA 200601-01 and an updated eBuild to address this issue. Users may apply this update by executing the following commands as a superuser:
emerge --sync
emerge --ask --oneshot --verbose ">=app-crypt/pinentry-0.7.2-r2"
References
Gentoo Pinentry Local Privilege Escalation Vulnerability
References:
References: