NX Server 'nxconfigure.sh' Local Privilege Escalation Vulnerability
BID:49720
Info
NX Server 'nxconfigure.sh' Local Privilege Escalation Vulnerability
| Bugtraq ID: | 49720 |
| Class: | Design Error |
| CVE: |
CVE-2011-3977 |
| Remote: | No |
| Local: | Yes |
| Published: | Sep 21 2011 12:00AM |
| Updated: | Jan 23 2012 06:50PM |
| Credit: | Gian Filippo Pinzari |
| Vulnerable: |
NoMachine NX Server 3.5 Gentoo Linux |
| Not Vulnerable: |
NoMachine NX Server 3.5.0-5 NoMachine NX Server 3.5.0-2 |
Discussion
NX Server 'nxconfigure.sh' Local Privilege Escalation Vulnerability
NX Server is prone to a local privilege-escalation vulnerability. Attackers can exploit this issue to read arbitrary files with superuser privileges. Information obtained may aid in further attacks.
NX Server 3.5.0 is vulnerable; other versions may also be affected.
NX Server is prone to a local privilege-escalation vulnerability. Attackers can exploit this issue to read arbitrary files with superuser privileges. Information obtained may aid in further attacks.
NX Server 3.5.0 is vulnerable; other versions may also be affected.
Exploit / POC
NX Server 'nxconfigure.sh' Local Privilege Escalation Vulnerability
Attacker can exploit this issue through the command line.
Attacker can exploit this issue through the command line.
Solution / Fix
NX Server 'nxconfigure.sh' Local Privilege Escalation Vulnerability
Solution:
Updates are available. Please see the references for more information.
Solution:
Updates are available. Please see the references for more information.
References
NX Server 'nxconfigure.sh' Local Privilege Escalation Vulnerability
References:
References:
- NX Server Home Page (NoMachine)
- NGS00099 Patch Notification: Vulnerable SUID script in (nomachine) (research)
- The nxconfigure.sh script can allow the execution of arbitrary commands on the s (Gian Filippo Pinzari)