Roxio Toast DejaVu Component PATH Variable Local Privilege Escalation Vulnerability
BID:19596
Info
Roxio Toast DejaVu Component PATH Variable Local Privilege Escalation Vulnerability
| Bugtraq ID: | 19596 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | No |
| Local: | Yes |
| Published: | Aug 18 2006 12:00AM |
| Updated: | Aug 29 2006 08:58PM |
| Credit: | Netragard, L.L.C is credited with the discovery of this vulnerability. |
| Vulnerable: |
Roxio Toast 7.Titanium |
| Not Vulnerable: | |
Discussion
Roxio Toast DejaVu Component PATH Variable Local Privilege Escalation Vulnerability
Roxio Toast is prone to a local privilege-escalation vulnerability because it fails to properly sanitize user-supplied input. As a result, local users may set their own search path for external applications that are called by setuid programs that are included in Roxio Toast.
This issue allows local attackers to gain superuser privileges, resulting in a complete compromise of affected computers.
This issue affects the DejaVu component that is installed by default in a standard installation of the vulnerable application. DejaVu is a third-party component that is maintained by Propaganda Productions. Roxio Toast version 7 Titanium includes the vulnerable component; other versions may also be affected.
Roxio Toast is prone to a local privilege-escalation vulnerability because it fails to properly sanitize user-supplied input. As a result, local users may set their own search path for external applications that are called by setuid programs that are included in Roxio Toast.
This issue allows local attackers to gain superuser privileges, resulting in a complete compromise of affected computers.
This issue affects the DejaVu component that is installed by default in a standard installation of the vulnerable application. DejaVu is a third-party component that is maintained by Propaganda Productions. Roxio Toast version 7 Titanium includes the vulnerable component; other versions may also be affected.
Exploit / POC
Roxio Toast DejaVu Component PATH Variable Local Privilege Escalation Vulnerability
The following exploit code is available:
The following exploit code is available:
Solution / Fix
Roxio Toast DejaVu Component PATH Variable Local Privilege Escalation Vulnerability
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected]:[email protected].
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected]:[email protected].
References
Roxio Toast DejaVu Component PATH Variable Local Privilege Escalation Vulnerability
References:
References:
- Roxio Homepage (Roxio)