S.u.S.E. 6.0 xtvscreen Vulnerability
BID:325
Info
S.u.S.E. 6.0 xtvscreen Vulnerability
| Bugtraq ID: | 325 |
| Class: | Origin Validation Error |
| CVE: |
CVE-1999-1495 |
| Remote: | No |
| Local: | Yes |
| Published: | Feb 18 1999 12:00AM |
| Updated: | Jul 11 2009 12:16AM |
| Credit: | First posted to bugtraq by Andre Cruz <[email protected]> on February 18, 1999. |
| Vulnerable: |
SuSE Linux 6.0 |
| Not Vulnerable: | |
Discussion
S.u.S.E. 6.0 xtvscreen Vulnerability
xtvscreen is a screen capture utility shipped with SuSE Linux 6. It's supposed to create files in it's working directory to store the captured images. Unfortunately, it will also follow symlinks. Since xtvscreen is suid root by default, it will overwrite any file on the system.
xtvscreen is a screen capture utility shipped with SuSE Linux 6. It's supposed to create files in it's working directory to store the captured images. Unfortunately, it will also follow symlinks. Since xtvscreen is suid root by default, it will overwrite any file on the system.
Exploit / POC
S.u.S.E. 6.0 xtvscreen Vulnerability
Currently the SecurityFocus staff are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected].
Currently the SecurityFocus staff are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected].
Solution / Fix
S.u.S.E. 6.0 xtvscreen Vulnerability
Solution:
The quickest way to solve the problem is to chmod -s xtvscreen.
Solution:
The quickest way to solve the problem is to chmod -s xtvscreen.
References
S.u.S.E. 6.0 xtvscreen Vulnerability
References:
References: