SuSE YaST Module Search Path Local Privilege Escalation Vulnerability
BID:26634
Info
SuSE YaST Module Search Path Local Privilege Escalation Vulnerability
| Bugtraq ID: | 26634 |
| Class: | Design Error |
| CVE: |
CVE-2007-6167 |
| Remote: | No |
| Local: | Yes |
| Published: | Nov 22 2007 12:00AM |
| Updated: | Mar 19 2015 08:31AM |
| Credit: | Stefan Nordhausen is credited with the discovery of this issue. |
| Vulnerable: |
SuSE YaST2 SuSE SUSE Linux Enterprise Server 9 SuSE SUSE Linux Enterprise Server 8 SuSE SUSE Linux Enterprise Server 10 SP1 SuSE SUSE Linux Enterprise SDK 10.SP1 SuSE openSUSE 10.3 S.u.S.E. UnitedLinux 1.0 S.u.S.E. SuSE Linux Standard Server 8.0 S.u.S.E. SuSE Linux School Server for i386 S.u.S.E. SUSE LINUX Retail Solution 8.0 S.u.S.E. SuSE Linux Openexchange Server 4.0 S.u.S.E. openSUSE 10.2 S.u.S.E. Open-Enterprise-Server 0 S.u.S.E. Novell Linux POS 9 S.u.S.E. Novell Linux Desktop 9.0 S.u.S.E. Linux Desktop 1.0 S.u.S.E. Linux 10.1 x86-64 S.u.S.E. Linux 10.1 x86 S.u.S.E. Linux 10.1 ppc S.u.S.E. Linux 10.0 x86-64 S.u.S.E. Linux 10.0 x86 S.u.S.E. Linux 10.0 ppc |
| Not Vulnerable: | |
Discussion
SuSE YaST Module Search Path Local Privilege Escalation Vulnerability
SuSE YaST is prone to a local privilege-escalation vulnerability.
Exploiting this issue allows local attackers to execute arbitrary code with the privileges of the user running the affected application (typically superuser).
SuSE YaST is prone to a local privilege-escalation vulnerability.
Exploiting this issue allows local attackers to execute arbitrary code with the privileges of the user running the affected application (typically superuser).
Exploit / POC
SuSE YaST Module Search Path Local Privilege Escalation Vulnerability
An attacker can exploit this issue by gaining local interactive access to the affected computer.
An attacker can exploit this issue by gaining local interactive access to the affected computer.
Solution / Fix
SuSE YaST Module Search Path Local Privilege Escalation Vulnerability
Solution:
The vendor has released updates to address this issue. Please see the references for more information.
Solution:
The vendor has released updates to address this issue. Please see the references for more information.
References
SuSE YaST Module Search Path Local Privilege Escalation Vulnerability
References:
References:
- Vulnerability Summary CVE-2007-6167 (US-CERT)