FreeBSD BubbleMon Privilege Elevation Vulnerability
BID:2609
Info
FreeBSD BubbleMon Privilege Elevation Vulnerability
| Bugtraq ID: | 2609 |
| Class: | Access Validation Error |
| CVE: |
CVE-2001-0424 |
| Remote: | No |
| Local: | Yes |
| Published: | Apr 16 2001 12:00AM |
| Updated: | Jul 11 2009 06:06AM |
| Credit: | Reported to Bugtraq by Christer <[email protected]> on Mon, 16 Apr, 2001. |
| Vulnerable: |
Timecop BubbleMon 1.31 Timecop BubbleMon 1.23 Timecop BubbleMon 1.22 Timecop BubbleMon 1.21 test1 Timecop BubbleMon 1.21 Timecop BubbleMon 1.3 Timecop BubbleMon 1.2 test1 Timecop BubbleMon 1.2 Timecop BubbleMon 1.1 test7 Timecop BubbleMon 1.1 test6 Timecop BubbleMon 1.1 test5 Timecop BubbleMon 1.1 test4 Timecop BubbleMon 1.1 test3 Timecop BubbleMon 1.1 test2 Timecop BubbleMon 1.1 test1 Timecop BubbleMon 1.1 Timecop BubbleMon 1.0 pl9 Timecop BubbleMon 1.0 pl8 Timecop BubbleMon 1.0 pl7 Timecop BubbleMon 1.0 pl6 Timecop BubbleMon 1.0 pl4 Timecop BubbleMon 1.0 pl3 Timecop BubbleMon 1.0 pl2 Timecop BubbleMon 1.0 pl1 Timecop BubbleMon 1.0 |
| Not Vulnerable: |
Timecop BubbleMon 1.32 |
Discussion
FreeBSD BubbleMon Privilege Elevation Vulnerability
BubbleMon is a visual system monitor utility.
A feature of BubbleMon allows users to specify up to two programs or shell-scripts, with arguments, which will be executed on a lef- or middle-mouse click within the BubbleMon icon.
FreeBSD releases of BubbleMon, prior to the current version (1.32), willl execute these supplied commands with inappropriately high privilege. By creating a malicious script, then specifying its path to BubbleMon, an attacker can execute arbitrary commands with the privilege level of kmem.
BubbleMon is a visual system monitor utility.
A feature of BubbleMon allows users to specify up to two programs or shell-scripts, with arguments, which will be executed on a lef- or middle-mouse click within the BubbleMon icon.
FreeBSD releases of BubbleMon, prior to the current version (1.32), willl execute these supplied commands with inappropriately high privilege. By creating a malicious script, then specifying its path to BubbleMon, an attacker can execute arbitrary commands with the privilege level of kmem.
Exploit / POC
FreeBSD BubbleMon Privilege Elevation Vulnerability
Currently the SecurityFocus staff are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Currently the SecurityFocus staff are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.