wmtv local root Vulnerability
BID:3658
Info
wmtv local root Vulnerability
| Bugtraq ID: | 3658 |
| Class: | Configuration Error |
| CVE: |
CVE-2001-1272 |
| Remote: | No |
| Local: | Yes |
| Published: | Dec 06 2001 12:00AM |
| Updated: | Jul 11 2009 09:06AM |
| Credit: | Debian's security advisory credits Nicolas Boullis with discovery. |
| Vulnerable: |
wliang wmtv 0.6.5 |
| Not Vulnerable: | |
Discussion
wmtv local root Vulnerability
wmtv, a video4linux TV player for windowmaker, is installed setuid root. This program can run an external command when you double click on the TV window, with the command specified by the -e command line option. Since the program is suid root this command is run with root privileges, allowing for extremely trivial exploit.
Debian GNU/Linux 2.2 systems which have wmtv installed are vulnerable to this, other distributionts may suffer from it as well.
wmtv, a video4linux TV player for windowmaker, is installed setuid root. This program can run an external command when you double click on the TV window, with the command specified by the -e command line option. Since the program is suid root this command is run with root privileges, allowing for extremely trivial exploit.
Debian GNU/Linux 2.2 systems which have wmtv installed are vulnerable to this, other distributionts may suffer from it as well.
Exploit / POC
wmtv local root Vulnerability
Currently the SecurityFocus staff are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Currently the SecurityFocus staff are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution / Fix
wmtv local root Vulnerability
Solution:
Currently the SecurityFocus staff are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution:
Currently the SecurityFocus staff are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.