Autorun Arbitrary File Read Vulnerability
BID:4884
Info
Autorun Arbitrary File Read Vulnerability
| Bugtraq ID: | 4884 |
| Class: | Unknown |
| CVE: |
CVE-2002-0915 |
| Remote: | No |
| Local: | Yes |
| Published: | May 29 2002 12:00AM |
| Updated: | Jul 11 2009 01:56PM |
| Credit: | Credited to KF <[email protected]>. |
| Vulnerable: |
Harald Hoyer autorun 2.7 |
| Not Vulnerable: | |
Discussion
Autorun Arbitrary File Read Vulnerability
Autorun is a setuid binary that is part of Xandros based Linux distributions.
A vulnerability exists in versions of autorun based on Xandros Linux. Reportedly, it is possible to view files on a vulnerable system by specifying a filename as an argument to the -c option. This occurs with effective root privileges. An attacker may exploit this vulnerability to view some of the contents of restricted files.
Autorun is a setuid binary that is part of Xandros based Linux distributions.
A vulnerability exists in versions of autorun based on Xandros Linux. Reportedly, it is possible to view files on a vulnerable system by specifying a filename as an argument to the -c option. This occurs with effective root privileges. An attacker may exploit this vulnerability to view some of the contents of restricted files.