Dia 'PySys_SetArgv' Remote Command Execution Vulnerability
BID:33448
Info
Dia 'PySys_SetArgv' Remote Command Execution Vulnerability
| Bugtraq ID: | 33448 |
| Class: | Design Error |
| CVE: |
CVE-2008-5984 |
| Remote: | Yes |
| Local: | No |
| Published: | Jan 26 2009 12:00AM |
| Updated: | Apr 16 2015 05:42PM |
| Credit: | James Vega |
| Vulnerable: |
RedHat Linux 4.0 RedHat Linux 2.1 RedHat Enterprise Linux WS 4 RedHat Enterprise Linux WS 2.1 RedHat Enterprise Linux ES 4 RedHat Enterprise Linux ES 2.1 Red Hat Enterprise Linux AS 4 Red Hat Enterprise Linux AS 2.1 Mandriva Linux Mandrake 2009.0 x86_64 Mandriva Linux Mandrake 2009.0 Mandriva Linux Mandrake 2008.1 x86_64 Mandriva Linux Mandrake 2008.1 Mandriva Linux Mandrake 2008.0 x86_64 Mandriva Linux Mandrake 2008.0 MandrakeSoft Corporate Server 3.0 x86_64 MandrakeSoft Corporate Server 3.0 GNOME Dia 0.96.1 Debian Linux 4.0 sparc Debian Linux 4.0 s/390 Debian Linux 4.0 powerpc Debian Linux 4.0 mipsel Debian Linux 4.0 mips Debian Linux 4.0 m68k Debian Linux 4.0 ia-64 Debian Linux 4.0 ia-32 Debian Linux 4.0 hppa Debian Linux 4.0 arm Debian Linux 4.0 amd64 Debian Linux 4.0 alpha Debian Linux 4.0 |
| Not Vulnerable: | |
Discussion
Dia 'PySys_SetArgv' Remote Command Execution Vulnerability
Dia is prone to a remote command-execution vulnerability.
An attacker could exploit this issue by enticing an unsuspecting victim to execute the vulnerable application in a directory containing a malicious Python file. A successful exploit will allow arbitrary Python commands to run with the privileges of the currently logged-in user.
Dia is prone to a remote command-execution vulnerability.
An attacker could exploit this issue by enticing an unsuspecting victim to execute the vulnerable application in a directory containing a malicious Python file. A successful exploit will allow arbitrary Python commands to run with the privileges of the currently logged-in user.
Exploit / POC
Dia 'PySys_SetArgv' Remote Command Execution Vulnerability
An attacker may exploit this issue using commonly available tools.
Core Security Technologies has developed a working commercial exploit for its CORE IMPACT product. This exploit is not otherwise publicly available or known to be circulating in the wild.
An attacker may exploit this issue using commonly available tools.
Core Security Technologies has developed a working commercial exploit for its CORE IMPACT product. This exploit is not otherwise publicly available or known to be circulating in the wild.
Solution / Fix
Dia 'PySys_SetArgv' Remote Command Execution Vulnerability
Solution:
Updates are available. Please see the references for more information.
Mandriva Linux Mandrake 2008.1 x86_64
Mandriva Linux Mandrake 2008.1
Mandriva Linux Mandrake 2009.0
Mandriva Linux Mandrake 2009.0 x86_64
Mandriva Linux Mandrake 2008.0 x86_64
Mandriva Linux Mandrake 2008.0
MandrakeSoft Corporate Server 3.0 x86_64
MandrakeSoft Corporate Server 3.0
Solution:
Updates are available. Please see the references for more information.
Mandriva Linux Mandrake 2008.1 x86_64
-
Mandriva dia-0.96.1-3.1mdv2008.1.x86_64.rpm
http://www.mandriva.com/en/download/
Mandriva Linux Mandrake 2008.1
-
Mandriva dia-0.96.1-3.1mdv2008.1.i586.rpm
http://www.mandriva.com/en/download/
Mandriva Linux Mandrake 2009.0
-
Mandriva dia-0.96.1-4.1mdv2009.0.i586.rpm
http://www.mandriva.com/en/download/
Mandriva Linux Mandrake 2009.0 x86_64
-
Mandriva dia-0.96.1-4.1mdv2009.0.x86_64.rpm
http://www.mandriva.com/en/download/
Mandriva Linux Mandrake 2008.0 x86_64
-
Mandriva dia-0.96.1-2.1mdv2008.0.x86_64.rpm
http://www.mandriva.com/en/download/
Mandriva Linux Mandrake 2008.0
-
Mandriva dia-0.96.1-2.1mdv2008.0.i586.rpm
http://www.mandriva.com/en/download/
MandrakeSoft Corporate Server 3.0 x86_64
-
Mandriva dia-0.92.2-2.4.C30mdk.x86_64.rpm
http://www.mandriva.com/en/download/
MandrakeSoft Corporate Server 3.0
-
Mandriva dia-0.92.2-2.4.C30mdk.i586.rpm
http://www.mandriva.com/en/download/
References
Dia 'PySys_SetArgv' Remote Command Execution Vulnerability
References:
References:
- Dia Homepage (GNOME)
- dia: Python scripts load modules from current director (James Vega)
- dia: untrusted python modules search path (Jan Lieskovsky)