OProfile Multiple Security Vulnerabilities
BID:48241
Info
OProfile Multiple Security Vulnerabilities
| Bugtraq ID: | 48241 |
| Class: | Input Validation Error |
| CVE: |
CVE-2011-2473 CVE-2011-2471 CVE-2011-2472 |
| Remote: | Yes |
| Local: | No |
| Published: | Jun 13 2011 12:00AM |
| Updated: | Dec 24 2014 12:55AM |
| Credit: | Stephane Chauveau <br> |
| Vulnerable: |
Ubuntu Ubuntu Linux 10.04 sparc Ubuntu Ubuntu Linux 10.04 powerpc Ubuntu Ubuntu Linux 10.04 i386 Ubuntu Ubuntu Linux 10.04 ARM Ubuntu Ubuntu Linux 10.04 amd64 OProfile OProfile 0.9.6 Gentoo Linux |
| Not Vulnerable: | |
Discussion
OProfile Multiple Security Vulnerabilities
OProfile is prone to multiple local privilege-escalation vulnerabilities, a directory-traversal vulnerability, and an arbitrary-file-upload vulnerability. These issues exist because the application fails to sanitize user-supplied input.
An attacker can exploit these issues to obtain sensitive information and to upload arbitrary code and run it in the context of the webserver process.
OProfile 0.9.6 is vulnerable; other versions may also be affected.
OProfile is prone to multiple local privilege-escalation vulnerabilities, a directory-traversal vulnerability, and an arbitrary-file-upload vulnerability. These issues exist because the application fails to sanitize user-supplied input.
An attacker can exploit these issues to obtain sensitive information and to upload arbitrary code and run it in the context of the webserver process.
OProfile 0.9.6 is vulnerable; other versions may also be affected.
Exploit / POC
OProfile Multiple Security Vulnerabilities
Attackers can exploit these issues with a browser.
Attackers can exploit these issues with a browser.
Solution / Fix
OProfile Multiple Security Vulnerabilities
Solution:
Updates are available. Please see the references for more information.
Solution:
Updates are available. Please see the references for more information.
References
OProfile Multiple Security Vulnerabilities
References:
References:
- OProfile Home Page (OProfile)
- Bug 700883 - (CVE-2011-1760) CVE-2011-1760 oprofile: Local privilege escalation (Jan Lieskovsky)
- Debian Bug report logs - #624212 (Stephane Chauveau)
- DSA-2254-1 oprofile -- command injection (Debian )