Inotify Incron File Permission Bypass Weakness
BID:22305
Info
Inotify Incron File Permission Bypass Weakness
| Bugtraq ID: | 22305 |
| Class: | Design Error |
| CVE: |
CVE-2007-0636 |
| Remote: | No |
| Local: | Yes |
| Published: | Jan 30 2007 12:00AM |
| Updated: | May 12 2015 07:35PM |
| Credit: | This issue was disclosed by the vendor. |
| Vulnerable: |
Inotify Incron 0.3.4 Inotify Incron 0.3.3 Inotify Incron 0.3.2 Inotify Incron 0.3.1 Inotify Incron 0.3 |
| Not Vulnerable: |
Inotify Incron 0.3.5 |
Discussion
Inotify Incron File Permission Bypass Weakness
Inotify Incron is prone to a local security-bypass weakness that may permit attackers to monitor arbitrary files with elevated privileges.
An attacker may be able to exploit this issue to gain potentially sensitive information about arbitrary files.
Inotify Incron is prone to a local security-bypass weakness that may permit attackers to monitor arbitrary files with elevated privileges.
An attacker may be able to exploit this issue to gain potentially sensitive information about arbitrary files.
Exploit / POC
Solution / Fix
Inotify Incron File Permission Bypass Weakness
Solution:
The vendor has addressed this issue in Incron 0.3.5 and later versions.
Inotify Incron 0.3
Inotify Incron 0.3.1
Inotify Incron 0.3.2
Inotify Incron 0.3.3
Inotify Incron 0.3.4
Solution:
The vendor has addressed this issue in Incron 0.3.5 and later versions.
Inotify Incron 0.3
-
Inotify incron-0.5.1.tar.gz
http://inotify.aiken.cz/download/incron/incron-0.5.1.tar.gz
Inotify Incron 0.3.1
-
Inotify incron-0.5.1.tar.gz
http://inotify.aiken.cz/download/incron/incron-0.5.1.tar.gz
Inotify Incron 0.3.2
-
Inotify incron-0.5.1.tar.gz
http://inotify.aiken.cz/download/incron/incron-0.5.1.tar.gz
Inotify Incron 0.3.3
-
Inotify incron-0.5.1.tar.gz
http://inotify.aiken.cz/download/incron/incron-0.5.1.tar.gz
Inotify Incron 0.3.4
-
Inotify incron-0.5.1.tar.gz
http://inotify.aiken.cz/download/incron/incron-0.5.1.tar.gz
References
Inotify Incron File Permission Bypass Weakness
References:
References:
- Inotify Incron Changelog (Inotify)
- Vendor HomePage (Inotify)