SING Log Option Local Privilege Escalation Vulnerability
BID:26679
Info
SING Log Option Local Privilege Escalation Vulnerability
| Bugtraq ID: | 26679 |
| Class: | Design Error |
| CVE: |
CVE-2007-6211 |
| Remote: | No |
| Local: | Yes |
| Published: | Dec 03 2007 12:00AM |
| Updated: | Dec 07 2007 07:32PM |
| Credit: | Milen Rangelov is credited with discovering this issue. |
| Vulnerable: |
SING SING 1.1 Debian Linux 4.0 sparc Debian Linux 4.0 s/390 Debian Linux 4.0 powerpc Debian Linux 4.0 mipsel Debian Linux 4.0 mips Debian Linux 4.0 m68k Debian Linux 4.0 ia-64 Debian Linux 4.0 ia-32 Debian Linux 4.0 hppa Debian Linux 4.0 arm Debian Linux 4.0 amd64 Debian Linux 4.0 alpha Debian Linux 4.0 |
| Not Vulnerable: | |
Discussion
SING Log Option Local Privilege Escalation Vulnerability
SING is prone to a local privilege-escalation vulnerability.
Exploiting this issue may allow local attackers to gain elevated privileges, facilitating the complete compromise of affected computers.
SING 1.1 is vulnerable to this issue; other versions may also be affected.
SING is prone to a local privilege-escalation vulnerability.
Exploiting this issue may allow local attackers to gain elevated privileges, facilitating the complete compromise of affected computers.
SING 1.1 is vulnerable to this issue; other versions may also be affected.
Exploit / POC
SING Log Option Local Privilege Escalation Vulnerability
The following example SING session is available.
UPDATE (December 7, 2007): Additional exploit code is available.
The following example SING session is available.
UPDATE (December 7, 2007): Additional exploit code is available.
Solution / Fix
SING Log Option Local Privilege Escalation Vulnerability
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
SING SING 1.1
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
SING SING 1.1
-
Debian CVE-2007-6211.patch
http://bugs.debian.org/cgi-bin/bugreport.cgi?msg=21;filename=CVE-2007- 6211.patch;att=1;bug=454167
References
SING Log Option Local Privilege Escalation Vulnerability
References:
References:
- SING Homepage (SING)
- Re: sing (debian) vunlerability? (Moritz Muehlenhoff
) - sing (debian) vunlerability? (Milen Rangelov
)