Fedora 'system-config-network' Security Bypass Vulnerability
BID:29416
Info
Fedora 'system-config-network' Security Bypass Vulnerability
| Bugtraq ID: | 29416 |
| Class: | Access Validation Error |
| CVE: |
CVE-2008-2359 |
| Remote: | No |
| Local: | Yes |
| Published: | May 27 2008 12:00AM |
| Updated: | May 27 2008 12:00AM |
| Credit: | The vendor disclosed this issue. |
| Vulnerable: | |
| Not Vulnerable: |
Redhat system-config-network 1.5.10 |
Discussion
Fedora 'system-config-network' Security Bypass Vulnerability
The 'system-config-network' command is prone to a security-bypass vulnerability because the software fails to properly restrict access to certain functionality.
Local attackers can exploit this issue to bypass certain security restrictions and modify network configuration settings.
This issue affects 'system-config-network' 1.5.5-1.fc8. Other versions may also be vulnerable.
The 'system-config-network' command is prone to a security-bypass vulnerability because the software fails to properly restrict access to certain functionality.
Local attackers can exploit this issue to bypass certain security restrictions and modify network configuration settings.
This issue affects 'system-config-network' 1.5.5-1.fc8. Other versions may also be vulnerable.
Exploit / POC
Fedora 'system-config-network' Security Bypass Vulnerability
To exploit this issue, attackers can use standard commands.
To exploit this issue, attackers can use standard commands.
Solution / Fix
Fedora 'system-config-network' Security Bypass Vulnerability
Solution:
The vendor has released an advisory and updates. Please see the references for more information.
Solution:
The vendor has released an advisory and updates. Please see the references for more information.
References
Fedora 'system-config-network' Security Bypass Vulnerability
References:
References: