Novell Identity Manager Arbitrary Command Execution Vulnerability
BID:19688
CVE-2006-4506 |Info
Novell Identity Manager Arbitrary Command Execution Vulnerability
| Bugtraq ID: | 19688 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | No |
| Local: | Yes |
| Published: | Aug 18 2006 12:00AM |
| Updated: | Aug 31 2006 02:53PM |
| Credit: | The vendor disclosed this issue. |
| Vulnerable: |
Novell Identity Manager 3.0 |
| Not Vulnerable: | |
Discussion
Novell Identity Manager Arbitrary Command Execution Vulnerability
Novell Identity Manager is prone to an arbitrary command-execution vulnerability.
A local attacker can exploit this issue to execute arbitrary commands with superuser privileges. Exploiting this issue allows attackers to completely compromise affected computers.
Novell Identity Manager is prone to an arbitrary command-execution vulnerability.
A local attacker can exploit this issue to execute arbitrary commands with superuser privileges. Exploiting this issue allows attackers to completely compromise affected computers.
Exploit / POC
Novell Identity Manager Arbitrary Command Execution Vulnerability
A proof of concept is available.
A proof of concept is available.
Solution / Fix
Novell Identity Manager Arbitrary Command Execution Vulnerability
Solution:
The vendor has released a patch to address this issue. Please see the references for more information.
Novell Identity Manager 3.0
Solution:
The vendor has released a patch to address this issue. Please see the references for more information.
Novell Identity Manager 3.0
-
Novell idm30linux_unix2.tgz
http://support.novell.com/servlet/filedownload/ftf/idm30linux_unix2.tg z
References
Novell Identity Manager Arbitrary Command Execution Vulnerability
References:
References: