openSUSE Linux gtk2 Package Search Path Remote Command Execution Vulnerability
BID:34068
Info
openSUSE Linux gtk2 Package Search Path Remote Command Execution Vulnerability
| Bugtraq ID: | 34068 |
| Class: | Design Error |
| CVE: |
CVE-2009-0848 |
| Remote: | Yes |
| Local: | No |
| Published: | Mar 10 2009 12:00AM |
| Updated: | Mar 11 2009 04:46PM |
| Credit: | SUSE |
| Vulnerable: |
S.u.S.E. openSUSE 11.1 S.u.S.E. openSUSE 11.0 |
| Not Vulnerable: | |
Discussion
openSUSE Linux gtk2 Package Search Path Remote Command Execution Vulnerability
The openSUSE gtk2 package is prone to a remote command-execution vulnerability.
An attacker could exploit this issue by enticing an unsuspecting victim to run a vulnerable application in a directory containing a malicious module file with a specific name. A successful exploit will allow arbitrary commands to run with the privileges of the currently logged-in user.
openSUSE 11.0 and 11.1 are vulnerable.
The openSUSE gtk2 package is prone to a remote command-execution vulnerability.
An attacker could exploit this issue by enticing an unsuspecting victim to run a vulnerable application in a directory containing a malicious module file with a specific name. A successful exploit will allow arbitrary commands to run with the privileges of the currently logged-in user.
openSUSE 11.0 and 11.1 are vulnerable.
Exploit / POC
openSUSE Linux gtk2 Package Search Path Remote Command Execution Vulnerability
An attacker may use commonly available tools to exploit this issue.
An attacker may use commonly available tools to exploit this issue.
Solution / Fix
openSUSE Linux gtk2 Package Search Path Remote Command Execution Vulnerability
Solution:
The vendor has released an advisory and updates. Please see the references for details.
Solution:
The vendor has released an advisory and updates. Please see the references for details.
References
openSUSE Linux gtk2 Package Search Path Remote Command Execution Vulnerability
References:
References:
- openSUSE Homepage (SUSE)