Dag Wieers Dstat 'sys.path' Search Path Local Privilege Escalation Vulnerability
BID:37131
Info
Dag Wieers Dstat 'sys.path' Search Path Local Privilege Escalation Vulnerability
| Bugtraq ID: | 37131 |
| Class: | Design Error |
| CVE: |
CVE-2009-3894 CVE-2009-4081 |
| Remote: | No |
| Local: | Yes |
| Published: | Nov 25 2009 12:00AM |
| Updated: | Jan 11 2010 08:31AM |
| Credit: | Robert Buchholz from Gentoo Security Team |
| Vulnerable: |
Red Hat Fedora 12 Red Hat Fedora 11 Red Hat Enterprise Linux Desktop 5 client Red Hat Enterprise Linux 5 Server Pardus Linux 2009 0 MandrakeSoft Corporate Server 4.0 x86_64 MandrakeSoft Corporate Server 4.0 Gentoo Linux Dag Wieers dstat 0.6.9 Avaya Aura System Platform SP1.1 Avaya Aura System Platform 6.0 |
| Not Vulnerable: |
Dag Wieers dstat 0.7 |
Discussion
Dag Wieers Dstat 'sys.path' Search Path Local Privilege Escalation Vulnerability
Dag Wieers Dstat is prone to a local privilege-escalation vulnerability.
Local attackers can exploit this issue to execute arbitrary code with the privileges of the user running the affected application. Successful exploits may aid in the compromise of affected computers.
Versions prior to Dstat 0.7.0 are vulnerable.
Dag Wieers Dstat is prone to a local privilege-escalation vulnerability.
Local attackers can exploit this issue to execute arbitrary code with the privileges of the user running the affected application. Successful exploits may aid in the compromise of affected computers.
Versions prior to Dstat 0.7.0 are vulnerable.
Exploit / POC
Dag Wieers Dstat 'sys.path' Search Path Local Privilege Escalation Vulnerability
To exploit this issue, an attacker must have local access to an affected computer and must entice an unsuspecting user to run the dstat command on a crafted Python module.
To exploit this issue, an attacker must have local access to an affected computer and must entice an unsuspecting user to run the dstat command on a crafted Python module.
Solution / Fix
Dag Wieers Dstat 'sys.path' Search Path Local Privilege Escalation Vulnerability
Solution:
Updates are available. Please see the references for more information.
MandrakeSoft Corporate Server 4.0
Dag Wieers dstat 0.6.9
MandrakeSoft Corporate Server 4.0 x86_64
Solution:
Updates are available. Please see the references for more information.
MandrakeSoft Corporate Server 4.0
-
Mandriva dstat-0.6.1-1.1.20060mlcs4.noarch.rpm
http://www.mandriva.com/en/download/
Dag Wieers dstat 0.6.9
-
Dag Wieers dstat-0.7.0.tar.bz2
http://dag.wieers.com/home-made/dstat/dstat-0.7.0.tar.bz2
MandrakeSoft Corporate Server 4.0 x86_64
-
Mandriva dstat-0.6.1-1.1.20060mlcs4.noarch.rpm
http://www.mandriva.com/en/download/
References
Dag Wieers Dstat 'sys.path' Search Path Local Privilege Escalation Vulnerability
References:
References: