Debian 'extplorer' Package Insecure File Permissions Vulnerability
BID:54801
Info
Debian 'extplorer' Package Insecure File Permissions Vulnerability
| Bugtraq ID: | 54801 |
| Class: | Design Error |
| CVE: |
CVE-2012-3454 |
| Remote: | No |
| Local: | Yes |
| Published: | Aug 03 2012 12:00AM |
| Updated: | Aug 03 2012 12:00AM |
| Credit: | Andreas Beckmann |
| Vulnerable: |
Debian extplorer 2.1.0b6+dfsg.3-3 |
| Not Vulnerable: | |
Discussion
Debian 'extplorer' Package Insecure File Permissions Vulnerability
extplorer is prone to an insecure file-permission vulnerability.
A local attacker can exploit this issue to delete and replace the files with arbitrary data. This may aid in further attacks.
extplorer 2.1.0b6+dfsg.3-3 is vulnerable; other versions may be vulnerable.
extplorer is prone to an insecure file-permission vulnerability.
A local attacker can exploit this issue to delete and replace the files with arbitrary data. This may aid in further attacks.
extplorer 2.1.0b6+dfsg.3-3 is vulnerable; other versions may be vulnerable.
Exploit / POC
Debian 'extplorer' Package Insecure File Permissions Vulnerability
Attackers require local interactive access to exploit this issue.
Attackers require local interactive access to exploit this issue.
References
Debian 'extplorer' Package Insecure File Permissions Vulnerability
References:
References:
- Debian Homepage (Debian)