Mandriva 'initscripts' Local Information Disclosure Vulnerability
BID:35854
Info
Mandriva 'initscripts' Local Information Disclosure Vulnerability
| Bugtraq ID: | 35854 |
| Class: | Design Error |
| CVE: | |
| Remote: | No |
| Local: | Yes |
| Published: | Jul 28 2009 12:00AM |
| Updated: | Jul 29 2009 05:45PM |
| Credit: | Philippe |
| Vulnerable: |
Mandriva Linux Mandrake 2009.1 x86_64 Mandriva Linux Mandrake 2009.1 Mandriva Linux Mandrake 2009.0 x86_64 Mandriva Linux Mandrake 2009.0 Mandriva Linux Mandrake 2008.1 x86_64 Mandriva Linux Mandrake 2008.1 MandrakeSoft Enterprise Server 5 x86_64 MandrakeSoft Enterprise Server 5 |
| Not Vulnerable: | |
Discussion
Mandriva 'initscripts' Local Information Disclosure Vulnerability
The Mandriva 'initscripts' package is prone to a local information-disclosure vulnerability.
Successfully exploiting this issue allows attackers to obtain sensitive information that may aid in further attacks.
The Mandriva 'initscripts' package is prone to a local information-disclosure vulnerability.
Successfully exploiting this issue allows attackers to obtain sensitive information that may aid in further attacks.
Exploit / POC
Mandriva 'initscripts' Local Information Disclosure Vulnerability
An attacker can use standard tools to exploit this issue.
An attacker can use standard tools to exploit this issue.
Solution / Fix
Mandriva 'initscripts' Local Information Disclosure Vulnerability
Solution:
The vendor has released updates and an advisory. Please see the references for details.
Mandriva Linux Mandrake 2009.0 x86_64
Mandriva Linux Mandrake 2008.1 x86_64
Mandriva Linux Mandrake 2009.0
Mandriva Linux Mandrake 2009.1
Mandriva Linux Mandrake 2008.1
MandrakeSoft Enterprise Server 5 x86_64
Mandriva Linux Mandrake 2009.1 x86_64
MandrakeSoft Enterprise Server 5
Solution:
The vendor has released updates and an advisory. Please see the references for details.
Mandriva Linux Mandrake 2009.0 x86_64
-
Mandriva initscripts-8.81-10.2mdv2009.0.x86_64.rpm
http://www.mandriva.com/en/download/
Mandriva Linux Mandrake 2008.1 x86_64
-
Mandriva initscripts-8.63-9.4mdv2008.1.x86_64.rpm
http://www.mandriva.com/en/download/
Mandriva Linux Mandrake 2009.0
-
Mandriva initscripts-8.81-10.2mdv2009.0.i586.rpm
http://www.mandriva.com/en/download/
Mandriva Linux Mandrake 2009.1
-
Mandriva initscripts-8.88-23.2mdv2009.1.i586.rpm
http://www.mandriva.com/en/download/
Mandriva Linux Mandrake 2008.1
-
Mandriva initscripts-8.63-9.4mdv2008.1.i586.rpm
http://www.mandriva.com/en/download/
MandrakeSoft Enterprise Server 5 x86_64
-
Mandriva initscripts-8.81-10.2mdvmes5.x86_64.rpm
http://www.mandriva.com/en/download/
Mandriva Linux Mandrake 2009.1 x86_64
-
Mandriva initscripts-8.88-23.2mdv2009.1.x86_64.rpm
http://www.mandriva.com/en/download/
MandrakeSoft Enterprise Server 5
-
Mandriva initscripts-8.81-10.2mdvmes5.i586.rpm
http://www.mandriva.com/en/download/
References
Mandriva 'initscripts' Local Information Disclosure Vulnerability
References:
References:
- Bug 52149 - [2010 Alpha1] A part of the wireless key is logged (Mandriva)
- Mandriva Homepage (Mandriva)