abrt Race Condition Local Privilege Escalation Vulnerability
BID:57662
Info
abrt Race Condition Local Privilege Escalation Vulnerability
| Bugtraq ID: | 57662 |
| Class: | Race Condition Error |
| CVE: |
CVE-2012-5660 |
| Remote: | No |
| Local: | Yes |
| Published: | Jan 31 2013 12:00AM |
| Updated: | Jan 31 2013 12:00AM |
| Credit: | Martin Carpenter of Citco |
| Vulnerable: |
Red Hat Enterprise Linux Workstation 6 Red Hat Enterprise Linux Server 6 Red Hat Enterprise Linux HPC Node 6 Red Hat Enterprise Linux Desktop 6 CentOS CentOS 6 |
| Not Vulnerable: | |
Discussion
abrt Race Condition Local Privilege Escalation Vulnerability
abrt is prone to a local privilege-escalation vulnerability.
An attacker can exploit this issue by conducting a symlink attack.
A local attacker can exploit this vulnerability to gain root privileges.
abrt is prone to a local privilege-escalation vulnerability.
An attacker can exploit this issue by conducting a symlink attack.
A local attacker can exploit this vulnerability to gain root privileges.
Exploit / POC
abrt Race Condition Local Privilege Escalation Vulnerability
An attacker uses readily available commands to exploit the issue.
An attacker uses readily available commands to exploit the issue.
Solution / Fix
abrt Race Condition Local Privilege Escalation Vulnerability
Solution:
Vendor updates are available. Please see the references for more information.
Solution:
Vendor updates are available. Please see the references for more information.