DeviceKit Storage Device Label Local Privilege Escalation Vulnerability
BID:38652
Info
DeviceKit Storage Device Label Local Privilege Escalation Vulnerability
| Bugtraq ID: | 38652 |
| Class: | Design Error |
| CVE: | |
| Remote: | No |
| Local: | Yes |
| Published: | Aug 10 2009 12:00AM |
| Updated: | Aug 10 2009 12:00AM |
| Credit: | Pierre Ossman |
| Vulnerable: |
Red Hat Fedora 12 Red Hat Fedora 11 freedesktop.org DeviceKit 002 |
| Not Vulnerable: | |
Discussion
DeviceKit Storage Device Label Local Privilege Escalation Vulnerability
DeviceKit is prone to a local privilege-escalation vulnerability.
Local attackers can exploit this issue to execute arbitrary code with the privileges of the user running the affected application. Successful exploits may aid in the compromise of affected computers.
DeviceKit is prone to a local privilege-escalation vulnerability.
Local attackers can exploit this issue to execute arbitrary code with the privileges of the user running the affected application. Successful exploits may aid in the compromise of affected computers.
Exploit / POC
DeviceKit Storage Device Label Local Privilege Escalation Vulnerability
To exploit this issue, an attacker needs local access to an affected computer.
To exploit this issue, an attacker needs local access to an affected computer.
Solution / Fix
DeviceKit Storage Device Label Local Privilege Escalation Vulnerability
Solution:
Updates are available. Please see the references for more information.
Solution:
Updates are available. Please see the references for more information.
References
DeviceKit Storage Device Label Local Privilege Escalation Vulnerability
References:
References:
- Bug 23235 cannot mount disc with / (slash) in label (Pierre Ossman)
- Bug 523178 - DeviceKit: Privilege escalation via pluggable storage device labels (Jan Lieskovsky )
- Commit Bug 23235 �?? Cannot mount disc with / (slash) in label (David Zeuthen)
- DeviceKit Homepage (freedesktop.org)