SSH Tectia Manager Agent Process Local Privilege Escalation Vulnerability
BID:19677
CVE-2006-4316 |Info
SSH Tectia Manager Agent Process Local Privilege Escalation Vulnerability
| Bugtraq ID: | 19677 |
| Class: | Design Error |
| CVE: | |
| Remote: | No |
| Local: | Yes |
| Published: | Aug 23 2006 12:00AM |
| Updated: | Aug 31 2006 12:13AM |
| Credit: | This issue was disclosed by the vendor. |
| Vulnerable: |
SSH Communications Security SSH Tectia Manager 2.1.2 SSH Communications Security SSH Tectia Manager 2.0 SSH Communications Security SSH Tectia Manager 1.4 SSH Communications Security SSH Tectia Manager 1.3 SSH Communications Security SSH Tectia Manager 1.2 |
| Not Vulnerable: |
SSH Communications Security SSH Tectia Manager 2.2 SSH Communications Security SSH Tectia Manager 2.1.3 |
Discussion
SSH Tectia Manager Agent Process Local Privilege Escalation Vulnerability
SSH Tectia Manager is prone to a local privilege-escalation vulnerability.
An attacker can exploit this issue to gain superuser access to a vulnerable computer. This may lead to other attacks. Successfully exploiting this issue will lead to the complete compromise of affected computers.
Version 2.1.2 and prior are vulnerable to this issue; other versions may also be affected.
SSH Tectia Manager is prone to a local privilege-escalation vulnerability.
An attacker can exploit this issue to gain superuser access to a vulnerable computer. This may lead to other attacks. Successfully exploiting this issue will lead to the complete compromise of affected computers.
Version 2.1.2 and prior are vulnerable to this issue; other versions may also be affected.
Exploit / POC
SSH Tectia Manager Agent Process Local Privilege Escalation Vulnerability
Attackers use standard system utilities to exploit this issue.
Attackers use standard system utilities to exploit this issue.
Solution / Fix
SSH Tectia Manager Agent Process Local Privilege Escalation Vulnerability
Solution:
The vendor has released an advisory to address this issue. Please see the referenced advisory for information on obtaining and applying fixes.
Solution:
The vendor has released an advisory to address this issue. Please see the referenced advisory for information on obtaining and applying fixes.
References
SSH Tectia Manager Agent Process Local Privilege Escalation Vulnerability
References:
References:
- SSH Tectia Management Agent Process Execution Vulnerability (SSH Tectia)
- SSH Tectia Manager Home Page (SSH Tectia )