Trickle 'LD_PRELOAD' Arbitrary Code Execution Vulnerability
BID:33516
Info
Trickle 'LD_PRELOAD' Arbitrary Code Execution Vulnerability
| Bugtraq ID: | 33516 |
| Class: | Design Error |
| CVE: |
CVE-2009-0415 |
| Remote: | No |
| Local: | Yes |
| Published: | Jan 29 2009 12:00AM |
| Updated: | May 07 2015 05:02PM |
| Credit: | Adeodato Simo |
| Vulnerable: |
Marius Aamodt Eriksen Trickle 1.06 |
| Not Vulnerable: | |
Discussion
Trickle 'LD_PRELOAD' Arbitrary Code Execution Vulnerability
Trickle is prone to a vulnerability that lets attackers execute arbitrary code.
An attacker may exploit this issue by enticing a legitimate user into running the affected application from a directory that contains a malicious library file.
Trickle is prone to a vulnerability that lets attackers execute arbitrary code.
An attacker may exploit this issue by enticing a legitimate user into running the affected application from a directory that contains a malicious library file.
Exploit / POC
Trickle 'LD_PRELOAD' Arbitrary Code Execution Vulnerability
To exploit this issue, an attacker would entice an unsuspecting victim to load a specially crafted library.
To exploit this issue, an attacker would entice an unsuspecting victim to load a specially crafted library.
Solution / Fix
Trickle 'LD_PRELOAD' Arbitrary Code Execution Vulnerability
Solution:
Vendor fixes are available. Please see the references for more information.
Solution:
Vendor fixes are available. Please see the references for more information.
References
Trickle 'LD_PRELOAD' Arbitrary Code Execution Vulnerability
References:
References:
- Trickle Homepage (Marius Aamodt Eriksen)
- trickle: may load arbitrary code from the current working directory (Adeodato Simo)