Security Readiness Review Evaluation Scripts Local Privilege Escalation Vulnerability
BID:37200
Info
Security Readiness Review Evaluation Scripts Local Privilege Escalation Vulnerability
| Bugtraq ID: | 37200 |
| Class: | Design Error |
| CVE: |
CVE-2009-4211 |
| Remote: | No |
| Local: | Yes |
| Published: | Dec 03 2009 12:00AM |
| Updated: | Dec 09 2009 09:04PM |
| Credit: | Frank Stuart |
| Vulnerable: |
United States Department of Defense Security Readiness Review Evaluation Scripts October 2009 United States Department of Defense Security Readiness Review Evaluation Scripts December 2009 |
| Not Vulnerable: | |
Discussion
Security Readiness Review Evaluation Scripts Local Privilege Escalation Vulnerability
Department of Defense Security Readiness Review Evaluation Scripts are prone to a local privilege-escalation vulnerability.
Local attackers can exploit this issue to execute arbitrary code with superuser privileges. Successful exploits will result in the complete compromise of affected computers.
Security Readiness Review Evaluation Scripts dated October, 2009 and December, 2009 are vulnerable; other versions may also be affected.
Department of Defense Security Readiness Review Evaluation Scripts are prone to a local privilege-escalation vulnerability.
Local attackers can exploit this issue to execute arbitrary code with superuser privileges. Successful exploits will result in the complete compromise of affected computers.
Security Readiness Review Evaluation Scripts dated October, 2009 and December, 2009 are vulnerable; other versions may also be affected.
Exploit / POC
Security Readiness Review Evaluation Scripts Local Privilege Escalation Vulnerability
An attacker can exploit this issue by enticing an unsuspecting administrator to run the affected application.
An attacker can exploit this issue by enticing an unsuspecting administrator to run the affected application.
Solution / Fix
Security Readiness Review Evaluation Scripts Local Privilege Escalation Vulnerability
Solution:
Currently we are not aware of any vendor-supplied patches. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
The vendor is working on updates to address this issue. This BID will be updated as more information becomes available.
Solution:
Currently we are not aware of any vendor-supplied patches. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
The vendor is working on updates to address this issue. This BID will be updated as more information becomes available.
References
Security Readiness Review Evaluation Scripts Local Privilege Escalation Vulnerability
References:
References:
- Security Readiness Review Evaluation Scripts Homepage (Department of Defense)
- U.S. Defense Information Systems Agency (DISA) Unix Security Readiness Review (S (Frank Stuart
) - UPDATE: DISA Unix SRR root compromise / CVE-2009-4211 / VU#433821 (Frank Stuart
) - Vulnerability Note VU#433821 DISA UNIX SRR scripts execute untrusted programs as (US-CERT)