Red Hat Directory Server 7.1 Local Insecure Permissions Vulnerability
BID:28204
Info
Red Hat Directory Server 7.1 Local Insecure Permissions Vulnerability
| Bugtraq ID: | 28204 |
| Class: | Access Validation Error |
| CVE: |
CVE-2008-0890 |
| Remote: | No |
| Local: | Yes |
| Published: | Mar 11 2008 12:00AM |
| Updated: | Mar 12 2008 08:51PM |
| Credit: | The vendor disclosed this issue. |
| Vulnerable: |
Redhat Directory Server 7.1 SP3 Redhat Directory Server 7.1 SP2 Redhat Directory Server 7.1 SP1 Redhat Directory Server 7.1 |
| Not Vulnerable: |
Redhat Directory Server 7.1 SP4 |
Discussion
Red Hat Directory Server 7.1 Local Insecure Permissions Vulnerability
Red Hat Directory Server is prone to an insecure-permissions vulnerability.
A local attacker can exploit this issue to execute arbitrary code with the privileges of the user running Directory Server or its applications.
Red Hat Directory Server 7.1 prior to Service Pack 4 is vulnerable.
Red Hat Directory Server is prone to an insecure-permissions vulnerability.
A local attacker can exploit this issue to execute arbitrary code with the privileges of the user running Directory Server or its applications.
Red Hat Directory Server 7.1 prior to Service Pack 4 is vulnerable.
Exploit / POC
Red Hat Directory Server 7.1 Local Insecure Permissions Vulnerability
To exploit this issue, an attacker requires local interactive access to a computer running the affected application.
To exploit this issue, an attacker requires local interactive access to a computer running the affected application.
Solution / Fix
Red Hat Directory Server 7.1 Local Insecure Permissions Vulnerability
Solution:
Red Hat has released an advisory and Directory Server 7.1 Service Pack 4 to address this issue. Please see the referenced advisory for more information.
Solution:
Red Hat has released an advisory and Directory Server 7.1 Service Pack 4 to address this issue. Please see the referenced advisory for more information.
References
Red Hat Directory Server 7.1 Local Insecure Permissions Vulnerability
References:
References:
- Red Hat Directory Server Homepage (Red Hat)
- Red Hat Homepage (Red Hat)
- RHSA-2008:0173-3 Red Hat Directory Server 7.1 Service Pack 4 security update (Red Hat)