Restorepoint Insecure File Permissions Local Privilege Escalation Vulnerability
BID:50991
Info
Restorepoint Insecure File Permissions Local Privilege Escalation Vulnerability
| Bugtraq ID: | 50991 |
| Class: | Design Error |
| CVE: |
CVE-2011-4202 |
| Remote: | No |
| Local: | Yes |
| Published: | Dec 08 2011 12:00AM |
| Updated: | Dec 08 2011 12:00AM |
| Credit: | Tavaris Desamito |
| Vulnerable: |
TADASoft Restorepoint 3.2 Evaluation |
| Not Vulnerable: |
TADASoft Restorepoint 3.3 Evaluation |
Discussion
Restorepoint Insecure File Permissions Local Privilege Escalation Vulnerability
Restorepoint is prone to a local privilege-escalation vulnerability because of an insecure file permission error.
A local attacker can exploit this vulnerability to gain root privileges.
Restorepoint 3.2 is affected; other versions may also be vulnerable.
Restorepoint is prone to a local privilege-escalation vulnerability because of an insecure file permission error.
A local attacker can exploit this vulnerability to gain root privileges.
Restorepoint 3.2 is affected; other versions may also be vulnerable.
Exploit / POC
Restorepoint Insecure File Permissions Local Privilege Escalation Vulnerability
An attacker requires local interactive access to exploit this issue.
An attacker requires local interactive access to exploit this issue.
Solution / Fix
Restorepoint Insecure File Permissions Local Privilege Escalation Vulnerability
Solution:
Updates are available. Please see the references for more information.
Solution:
Updates are available. Please see the references for more information.
References
Restorepoint Insecure File Permissions Local Privilege Escalation Vulnerability
References:
References:
- MATTA-2011-003 (Tavaris Desamito)
- Restorepoint Homepage (TADASoft )