AOL Security Edition Local Privilege Escalation Vulnerability
BID:19583
Info
AOL Security Edition Local Privilege Escalation Vulnerability
| Bugtraq ID: | 19583 |
| Class: | Design Error |
| CVE: |
CVE-2006-0948 |
| Remote: | No |
| Local: | Yes |
| Published: | Aug 18 2006 12:00AM |
| Updated: | Aug 29 2006 07:13PM |
| Credit: | Discovered by Carsten Eiram, Secunia Research. |
| Vulnerable: |
AOL AOL Security Edition 9.0 |
| Not Vulnerable: | |
Discussion
AOL Security Edition Local Privilege Escalation Vulnerability
AOL Security Edition is prone to a local privilege-escalation vulnerability.
This vulnerability arises because of insecure default permissions associated with directories, which can allow local attackers to place arbitrary executables in a directory that may be executed with elevated privileges.
AOL Security Edition 9.0 is reported vulnerable; other versions may be affected as well.
AOL Security Edition is prone to a local privilege-escalation vulnerability.
This vulnerability arises because of insecure default permissions associated with directories, which can allow local attackers to place arbitrary executables in a directory that may be executed with elevated privileges.
AOL Security Edition 9.0 is reported vulnerable; other versions may be affected as well.
Exploit / POC
AOL Security Edition Local Privilege Escalation Vulnerability
An exploit is not required.
An exploit is not required.
Solution / Fix
AOL Security Edition Local Privilege Escalation Vulnerability
Solution:
AOL has released fixes to address this issue. These fixes can be automatically applied by logging in to the service.
Solution:
AOL has released fixes to address this issue. These fixes can be automatically applied by logging in to the service.
References
AOL Security Edition Local Privilege Escalation Vulnerability
References:
References:
- AOL Home Page (AOL)
- AOL Insecure Default Directory Permissions (Secunia)