NVClock Local Privilege Escalation Vulnerability
BID:25052
Info
NVClock Local Privilege Escalation Vulnerability
| Bugtraq ID: | 25052 |
| Class: | Design Error |
| CVE: |
CVE-2007-3531 |
| Remote: | No |
| Local: | Yes |
| Published: | Jul 24 2007 12:00AM |
| Updated: | Apr 29 2009 11:46PM |
| Credit: | Tavis Ormandy of the Gentoo Linux Security Team disclosed this issue. |
| Vulnerable: |
NVClock NVClock 0.7 Gentoo Linux |
| Not Vulnerable: | |
Discussion
NVClock Local Privilege Escalation Vulnerability
NVClock is prone to a privilege-escalation vulnerability.
An attacker can exploit this issue to gain unauthorized access to local resources or gain escalated privileges on affected computers. Presumably, this utility runs with superuser privileges.
NVClock 0.7 is reported vulnerable; other versions may be affected as well.
NVClock is prone to a privilege-escalation vulnerability.
An attacker can exploit this issue to gain unauthorized access to local resources or gain escalated privileges on affected computers. Presumably, this utility runs with superuser privileges.
NVClock 0.7 is reported vulnerable; other versions may be affected as well.
Exploit / POC
NVClock Local Privilege Escalation Vulnerability
To exploit this issue, an attacker can use common filesystem utilities.
To exploit this issue, an attacker can use common filesystem utilities.
Solution / Fix
NVClock Local Privilege Escalation Vulnerability
Solution:
Please see references for advisories and more information.
Solution:
Please see references for advisories and more information.