system-config-printer Package 'pysmb.py' Local Privilege Escalation Vulnerability
BID:49288
Info
system-config-printer Package 'pysmb.py' Local Privilege Escalation Vulnerability
| Bugtraq ID: | 49288 |
| Class: | Design Error |
| CVE: |
CVE-2011-2899 |
| Remote: | No |
| Local: | Yes |
| Published: | Aug 04 2011 12:00AM |
| Updated: | Sep 08 2011 03:50PM |
| Credit: | Vincent Danen |
| Vulnerable: |
system-config-printer system-config-printer 1.1.3 system-config-printer system-config-printer 1.0 RedHat Enterprise Linux WS 4 RedHat Enterprise Linux ES 4 RedHat Enterprise Linux AS 4 RedHat Enterprise Linux Desktop version 4 RedHat Enterprise Linux 5 server Red Hat Enterprise Linux Desktop 5 client Avaya Proactive Contact 4.1.2 Avaya Proactive Contact 4.1.1 Avaya Proactive Contact 4.2.2 Avaya Proactive Contact 4.2.1 Avaya Proactive Contact 4.2 Avaya Proactive Contact 4.1 Avaya Proactive Contact 4.0.1 Avaya Proactive Contact 4.0 Avaya IQ 5.2 Avaya IQ 5.1.1 Avaya IQ 5.1 Avaya IQ 5 Avaya Aura System Manager 6.1.3 Avaya Aura System Manager 6.1.2 Avaya Aura System Manager 6.1.1 Avaya Aura System Manager 6.1 SP2 Avaya Aura System Manager 6.1 Sp1 Avaya Aura System Manager 6.1 Avaya Aura System Manager 6.0 SP1 Avaya Aura System Manager 6.0 Avaya Aura System Manager 5.2 Avaya Aura Presence Services 6.1.1 Avaya Aura Presence Services 6.1 Avaya Aura Presence Services 6.0 |
| Not Vulnerable: | |
Discussion
system-config-printer Package 'pysmb.py' Local Privilege Escalation Vulnerability
The 'system-config-printer' package is prone to a local privilege-escalation vulnerability.
Local attackers can exploit this issue to execute arbitrary code with the privileges of the user running the affected application. Successful exploits may aid in the compromise of affected computers.
The 'system-config-printer' package is prone to a local privilege-escalation vulnerability.
Local attackers can exploit this issue to execute arbitrary code with the privileges of the user running the affected application. Successful exploits may aid in the compromise of affected computers.
Exploit / POC
system-config-printer Package 'pysmb.py' Local Privilege Escalation Vulnerability
Attackers can use standard commands to exploit this issue.
Attackers can use standard commands to exploit this issue.
Solution / Fix
system-config-printer Package 'pysmb.py' Local Privilege Escalation Vulnerability
Solution:
Updates are available. Please see the references for more information.
Solution:
Updates are available. Please see the references for more information.
References
system-config-printer Package 'pysmb.py' Local Privilege Escalation Vulnerability
References:
References:
- Bug 728348 - (CVE-2011-2899) CVE-2011-2899 system-config-printer: possible arbit (Red Hat Bugzilla)
- system-config-printer Homepage (system-config-printer)
- ASA-2011-267 system-config-printer security update (RHSA-2011-1196) (Avaya)