Gentoo python-updater 'sys.path' Search Path Local Privilege Escalation Vulnerability
BID:43385
Info
Gentoo python-updater 'sys.path' Search Path Local Privilege Escalation Vulnerability
| Bugtraq ID: | 43385 |
| Class: | Design Error |
| CVE: | |
| Remote: | No |
| Local: | Yes |
| Published: | Sep 21 2010 12:00AM |
| Updated: | Sep 21 2010 12:00AM |
| Credit: | Robert Buchholz from Gentoo Security Team |
| Vulnerable: |
Gentoo Linux |
| Not Vulnerable: | |
Discussion
Gentoo python-updater 'sys.path' Search Path Local Privilege Escalation Vulnerability
Gentoo python-updater is prone to a local privilege-escalation vulnerability.
Local attackers can exploit this issue to execute arbitrary code with the privileges of the user running the affected application. Successful exploits may aid in the compromise of affected computers.
python-updater versions prior to 0.7-r1 are vulnerable.
Gentoo python-updater is prone to a local privilege-escalation vulnerability.
Local attackers can exploit this issue to execute arbitrary code with the privileges of the user running the affected application. Successful exploits may aid in the compromise of affected computers.
python-updater versions prior to 0.7-r1 are vulnerable.
Exploit / POC
Gentoo python-updater 'sys.path' Search Path Local Privilege Escalation Vulnerability
To exploit this issue, an attacker must have local access to an affected computer and must entice an unsuspecting user to run the python-updater command on a crafted Python module.
To exploit this issue, an attacker must have local access to an affected computer and must entice an unsuspecting user to run the python-updater command on a crafted Python module.
Solution / Fix
Gentoo python-updater 'sys.path' Search Path Local Privilege Escalation Vulnerability
Solution:
Updates are available. Please see the references for more information.
Solution:
Updates are available. Please see the references for more information.
References
Gentoo python-updater 'sys.path' Search Path Local Privilege Escalation Vulnerability
References:
References: