debian-goodies Checkrestart Script Local Privilege Escalation Vulnerability
BID:25569
Info
debian-goodies Checkrestart Script Local Privilege Escalation Vulnerability
| Bugtraq ID: | 25569 |
| Class: | Input Validation Error |
| CVE: |
CVE-2007-3912 |
| Remote: | No |
| Local: | Yes |
| Published: | Sep 06 2007 12:00AM |
| Updated: | Mar 24 2008 08:30PM |
| Credit: | Thomas de Grenier de Latour is credited with the discovery of this vulnerability. |
| Vulnerable: |
Ubuntu Ubuntu Linux 7.04 sparc Ubuntu Ubuntu Linux 7.04 powerpc Ubuntu Ubuntu Linux 7.04 i386 Ubuntu Ubuntu Linux 7.04 amd64 Ubuntu Ubuntu Linux 6.10 sparc Ubuntu Ubuntu Linux 6.10 powerpc Ubuntu Ubuntu Linux 6.10 i386 Ubuntu Ubuntu Linux 6.10 amd64 Ubuntu Ubuntu Linux 6.06 LTS sparc Ubuntu Ubuntu Linux 6.06 LTS powerpc Ubuntu Ubuntu Linux 6.06 LTS i386 Ubuntu Ubuntu Linux 6.06 LTS amd64 Debian Linux 3.1 sparc Debian Linux 3.1 s/390 Debian Linux 3.1 ppc Debian Linux 3.1 mipsel Debian Linux 3.1 mips Debian Linux 3.1 m68k Debian Linux 3.1 ia-64 Debian Linux 3.1 ia-32 Debian Linux 3.1 hppa Debian Linux 3.1 arm Debian Linux 3.1 amd64 Debian Linux 3.1 alpha Debian Linux 3.1 Debian Linux 4.0 sparc Debian Linux 4.0 s/390 Debian Linux 4.0 powerpc Debian Linux 4.0 mipsel Debian Linux 4.0 mips Debian Linux 4.0 m68k Debian Linux 4.0 ia-64 Debian Linux 4.0 ia-32 Debian Linux 4.0 hppa Debian Linux 4.0 arm Debian Linux 4.0 amd64 Debian Linux 4.0 alpha Debian Linux 4.0 Debian debian-goodies 0.33 Debian debian-goodies 0.27 |
| Not Vulnerable: |
Debian debian-goodies 0.34 |
Discussion
debian-goodies Checkrestart Script Local Privilege Escalation Vulnerability
The 'checkrestart' utility in the 'debian-goodies' package is prone to a local privilege-escalation vulnerability because the application fails to sufficiently validate user-supplied data.
An attacker can exploit this issue to execute arbitrary commands with superuser privileges. Successfully exploiting this issue will result in the complete compromise of affected computers.
This issue affects versions prior to debian-goodies 0.34.
The 'checkrestart' utility in the 'debian-goodies' package is prone to a local privilege-escalation vulnerability because the application fails to sufficiently validate user-supplied data.
An attacker can exploit this issue to execute arbitrary commands with superuser privileges. Successfully exploiting this issue will result in the complete compromise of affected computers.
This issue affects versions prior to debian-goodies 0.34.
Exploit / POC
debian-goodies Checkrestart Script Local Privilege Escalation Vulnerability
Currently we are not aware of any working exploits for this issue. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Currently we are not aware of any working exploits for this issue. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Solution / Fix
debian-goodies Checkrestart Script Local Privilege Escalation Vulnerability
Solution:
The vendor released updates to address this issue. Please see the references for more information.
Debian debian-goodies 0.27
Debian debian-goodies 0.33
Solution:
The vendor released updates to address this issue. Please see the references for more information.
Debian debian-goodies 0.27
-
Debian debian-goodies_0.35.tar.gz
http://ftp.de.debian.org/debian/pool/main/d/debian-goodies/debian-good ies_0.35.tar.gz
Debian debian-goodies 0.33
-
Debian debian-goodies_0.35.tar.gz
http://ftp.de.debian.org/debian/pool/main/d/debian-goodies/debian-good ies_0.35.tar.gz
References
debian-goodies Checkrestart Script Local Privilege Escalation Vulnerability
References:
References:
- debian-goodies Homepage (Debian)
- checkrestart: arbitrary root-privileged command execution (Thomas de Grenier de Latour)