SuSE YaST2 Backup File Name Local Arbitrary Shell Command Injection Vulnerability
BID:32464
Info
SuSE YaST2 Backup File Name Local Arbitrary Shell Command Injection Vulnerability
| Bugtraq ID: | 32464 |
| Class: | Input Validation Error |
| CVE: |
CVE-2008-4636 |
| Remote: | No |
| Local: | Yes |
| Published: | Nov 25 2008 12:00AM |
| Updated: | Mar 19 2015 09:32AM |
| Credit: | This issue was disclosed by the vendor. |
| Vulnerable: |
SuSE SUSE Linux Enterprise Server 9 SuSE SUSE Linux Enterprise Server 8 SuSE SUSE Linux Enterprise Server 10 SP2 SuSE SUSE Linux Enterprise Server 10 SP1 SuSE SUSE Linux Enterprise Desktop 10 SP2 SuSE SUSE Linux Enterprise Desktop 10 SP1 SuSE openSUSE 10.3 S.u.S.E. YaST2 Backup 0 S.u.S.E. openSUSE 11.0 S.u.S.E. openSUSE 10.2 S.u.S.E. Open-Enterprise-Server 0 S.u.S.E. Novell Linux POS 9 S.u.S.E. Novell Linux Desktop 9.0 |
| Not Vulnerable: | |
Discussion
SuSE YaST2 Backup File Name Local Arbitrary Shell Command Injection Vulnerability
SuSE YaST2 Backup is prone to a local command-injection vulnerability because it fails to adequately sanitize user-supplied input data.
Attackers can exploit this issue to execute arbitrary shell commands in the context of the vulnerable application. This may facilitate the complete compromise of affected computers.
SuSE YaST2 Backup is prone to a local command-injection vulnerability because it fails to adequately sanitize user-supplied input data.
Attackers can exploit this issue to execute arbitrary shell commands in the context of the vulnerable application. This may facilitate the complete compromise of affected computers.
Exploit / POC
SuSE YaST2 Backup File Name Local Arbitrary Shell Command Injection Vulnerability
An attacker with local, interactive access to a vulnerable computer can use readily available commands to exploit this issue.
An attacker with local, interactive access to a vulnerable computer can use readily available commands to exploit this issue.
Solution / Fix
SuSE YaST2 Backup File Name Local Arbitrary Shell Command Injection Vulnerability
Solution:
The vendor has released an advisory and fixes. Please see the references for more information.
S.u.S.E. openSUSE 10.3
S.u.S.E. openSUSE 10.2
S.u.S.E. openSUSE 11.0
Solution:
The vendor has released an advisory and fixes. Please see the references for more information.
S.u.S.E. openSUSE 10.3
-
S.u.S.E. yast2-backup-2.15.7-0.1.noarch.rpm
http://download.opensuse.org/pub/opensuse/update/10.3/rpm/noarch/yast2 -backup-2.15.7-0.1.noarch.rpm
S.u.S.E. openSUSE 10.2
-
S.u.S.E. yast2-backup-2.14.2-0.1.noarch.rpm
ftp://ftp.suse.com/pub/suse/update/10.2/rpm/noarch/yast2-backup-2.14.2 -0.1.noarch.rpm
S.u.S.E. openSUSE 11.0
-
S.u.S.E. yast2-backup-2.16.6-0.1.noarch.rpm
http://download.opensuse.org/pub/opensuse/update/11.0/rpm/noarch/yast2 -backup-2.16.6-0.1.noarch.rpm
References
SuSE YaST2 Backup File Name Local Arbitrary Shell Command Injection Vulnerability
References:
References: