Smartphone Pentest Framework CVE-2012-5697 Local Insecure File Permissions Vulnerability
BID:56707
Info
Smartphone Pentest Framework CVE-2012-5697 Local Insecure File Permissions Vulnerability
| Bugtraq ID: | 56707 |
| Class: | Design Error |
| CVE: |
CVE-2012-5697 |
| Remote: | No |
| Local: | Yes |
| Published: | Nov 14 2012 12:00AM |
| Updated: | Nov 14 2012 12:00AM |
| Credit: | High-Tech Bridge |
| Vulnerable: |
Bulb Security LLC Smartphone Pentest Framework 0.1.2 |
| Not Vulnerable: |
Bulb Security LLC Smartphone Pentest Framework 0.1.3 |
Discussion
Smartphone Pentest Framework CVE-2012-5697 Local Insecure File Permissions Vulnerability
Smartphone Pentest Framework is prone to a local insecure-file-permissions vulnerability.
An attacker can exploit this issue to read and modify arbitrary files; other attacks may also be possible.
Smartphone Pentest Framework 0.1.2 is vulnerable; other versions may also be affected.
Smartphone Pentest Framework is prone to a local insecure-file-permissions vulnerability.
An attacker can exploit this issue to read and modify arbitrary files; other attacks may also be possible.
Smartphone Pentest Framework 0.1.2 is vulnerable; other versions may also be affected.
Exploit / POC
Smartphone Pentest Framework CVE-2012-5697 Local Insecure File Permissions Vulnerability
A local attacker can use readily available tools to exploit this issue.
A local attacker can use readily available tools to exploit this issue.
Solution / Fix
Smartphone Pentest Framework CVE-2012-5697 Local Insecure File Permissions Vulnerability
Solution:
Updates are available. Please see the references for more information.
Solution:
Updates are available. Please see the references for more information.
References
Smartphone Pentest Framework CVE-2012-5697 Local Insecure File Permissions Vulnerability
References:
References:
- Multiple Vulnerabilities in Smartphone Pentest Framework (SPF) (High-Tech Bridge SA)
- Smartphone Pentest Framework Homepage (Bulb Security LLC)