OpenVAS Scanner Symlink Attack Local Privilege Escalation Vulnerability
BID:49460
Info
OpenVAS Scanner Symlink Attack Local Privilege Escalation Vulnerability
| Bugtraq ID: | 49460 |
| Class: | Unknown |
| CVE: | |
| Remote: | No |
| Local: | Yes |
| Published: | Sep 04 2011 12:00AM |
| Updated: | Sep 04 2011 12:00AM |
| Credit: | BugsNotHugs |
| Vulnerable: |
OpenVAS Project OpenVAS Scanner 3.2.4 |
| Not Vulnerable: | |
Discussion
OpenVAS Scanner Symlink Attack Local Privilege Escalation Vulnerability
OpenVAS Scanner is prone to a local privilege-escalation vulnerability.
Local attackers can exploit this issue to gain elevated privileges on affected computers.
OpenVAS Scanner 3.2.4 is vulnerable; others versions may also be affected.
OpenVAS Scanner is prone to a local privilege-escalation vulnerability.
Local attackers can exploit this issue to gain elevated privileges on affected computers.
OpenVAS Scanner 3.2.4 is vulnerable; others versions may also be affected.
Exploit / POC
OpenVAS Scanner Symlink Attack Local Privilege Escalation Vulnerability
An attacker can use readily available tools to exploit the issue.
An attacker can use readily available tools to exploit the issue.
Solution / Fix
OpenVAS Scanner Symlink Attack Local Privilege Escalation Vulnerability
Solution:
Currently, we are not aware of any vendor-supplied patches. If you feel we are in error or if you are aware of any more recent information, please mail us at: [email protected].
Solution:
Currently, we are not aware of any vendor-supplied patches. If you feel we are in error or if you are aware of any more recent information, please mail us at: [email protected].
References
OpenVAS Scanner Symlink Attack Local Privilege Escalation Vulnerability
References:
References:
- Product Homepage (OpenVAS)
- [Full-disclosure] openvas 2.x race condition (BugsNotHugs )