Quassel Core Insecure File Permissions Vulnerability
BID:50148
Info
Quassel Core Insecure File Permissions Vulnerability
| Bugtraq ID: | 50148 |
| Class: | Design Error |
| CVE: | |
| Remote: | No |
| Local: | Yes |
| Published: | Oct 14 2011 12:00AM |
| Updated: | Oct 14 2011 12:00AM |
| Credit: | Felix Geyer |
| Vulnerable: |
Ubuntu Ubuntu Linux 11.04 powerpc Ubuntu Ubuntu Linux 11.04 i386 Ubuntu Ubuntu Linux 11.04 ARM Ubuntu Ubuntu Linux 11.04 amd64 Ubuntu Ubuntu Linux 10.10 powerpc Ubuntu Ubuntu Linux 10.10 i386 Ubuntu Ubuntu Linux 10.10 ARM Ubuntu Ubuntu Linux 10.10 amd64 Ubuntu Ubuntu Linux 10.04 sparc Ubuntu Ubuntu Linux 10.04 powerpc Ubuntu Ubuntu Linux 10.04 i386 Ubuntu Ubuntu Linux 10.04 ARM Ubuntu Ubuntu Linux 10.04 amd64 |
| Not Vulnerable: | |
Discussion
Quassel Core Insecure File Permissions Vulnerability
Quassel Core is prone to an insecure file-permissions vulnerability.
An attacker can exploit this issue to obtain sensitive information such as an SSL certificate and the key file (/var/lib/quasselCert.pem). This may aid in further attacks.
Quassel Core is prone to an insecure file-permissions vulnerability.
An attacker can exploit this issue to obtain sensitive information such as an SSL certificate and the key file (/var/lib/quasselCert.pem). This may aid in further attacks.
Exploit / POC
Quassel Core Insecure File Permissions Vulnerability
Attackers can use readily available tools to exploit this issue.
Attackers can use readily available tools to exploit this issue.
Solution / Fix
Quassel Core Insecure File Permissions Vulnerability
Solution:
Updates are available. Please see the references for details.
Solution:
Updates are available. Please see the references for details.
References
Quassel Core Insecure File Permissions Vulnerability
References:
References:
- Quassel Homepage (Quassel IRC Team)
- quassel-core creates world-readable directories (Felix Geyer)