Wicd 'wicd.conf' Default Configuration Local Information Disclosure Vulnerability
BID:33658
Info
Wicd 'wicd.conf' Default Configuration Local Information Disclosure Vulnerability
| Bugtraq ID: | 33658 |
| Class: | Design Error |
| CVE: |
CVE-2009-0489 |
| Remote: | No |
| Local: | Yes |
| Published: | Feb 06 2009 12:00AM |
| Updated: | Apr 13 2009 06:46PM |
| Credit: | Tiziano Mueller of the Gentoo team |
| Vulnerable: |
Wicd Wicd 1.5.8 Slackware Linux 12.2 Slackware Linux -current Gentoo Linux |
| Not Vulnerable: |
Wicd Wicd 1.5.9 |
Discussion
Wicd 'wicd.conf' Default Configuration Local Information Disclosure Vulnerability
Wicd is prone to a local information-disclosure vulnerability because its default configuration fails to restrict ownership of its daemon.
Local attackers can exploit this issue to claim ownership of the Wicd daemon object and receive messages intended for the daemon. Information harvested from the messages could help attackers launch further attacks.
Versions prior to Wicd 1.5.9 are vulnerable.
Wicd is prone to a local information-disclosure vulnerability because its default configuration fails to restrict ownership of its daemon.
Local attackers can exploit this issue to claim ownership of the Wicd daemon object and receive messages intended for the daemon. Information harvested from the messages could help attackers launch further attacks.
Versions prior to Wicd 1.5.9 are vulnerable.
Exploit / POC
Wicd 'wicd.conf' Default Configuration Local Information Disclosure Vulnerability
Currently we are not aware of any working exploits. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Currently we are not aware of any working exploits. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Solution / Fix
Wicd 'wicd.conf' Default Configuration Local Information Disclosure Vulnerability
Solution:
The vendor released an update. Please see the references for more information.
Wicd Wicd 1.5.8
Solution:
The vendor released an update. Please see the references for more information.
Wicd Wicd 1.5.8
-
Wicd wicd-1.5.9.tar.gz
http://downloads.sourceforge.net/wicd/wicd-1.5.9.tar.gz?modtime=123396 3450&big_mirror=0
References
Wicd 'wicd.conf' Default Configuration Local Information Disclosure Vulnerability
References:
References:
- CVE Request - Wicd <= 1.5.8 (Robby Workman)
- Fix security holes in dbus config file. (Wicd)
- Wicd Homepage (Wicd)