autojump 'custom_install' Directory Local Privilege Escalation Vulnerability
BID:59498
Info
autojump 'custom_install' Directory Local Privilege Escalation Vulnerability
| Bugtraq ID: | 59498 |
| Class: | Unknown |
| CVE: |
CVE-2013-2012 |
| Remote: | No |
| Local: | Yes |
| Published: | Apr 25 2013 12:00AM |
| Updated: | Apr 25 2013 12:00AM |
| Credit: | Zbigniew Jedrzejewski-Szmek |
| Vulnerable: |
Joel Schaerer autojump 0 |
| Not Vulnerable: | |
Discussion
autojump 'custom_install' Directory Local Privilege Escalation Vulnerability
autojump is prone to a local privilege-escalation vulnerability.
Local attackers can exploit this issue to execute arbitrary python code with the privileges of the user running the application.
autojump is prone to a local privilege-escalation vulnerability.
Local attackers can exploit this issue to execute arbitrary python code with the privileges of the user running the application.
Exploit / POC
autojump 'custom_install' Directory Local Privilege Escalation Vulnerability
An attacker can exploit this issue using standard commands.
An attacker can exploit this issue using standard commands.
Solution / Fix
autojump 'custom_install' Directory Local Privilege Escalation Vulnerability
Solution:
Updates are available. Please see the references or vendor advisory for more information.
Solution:
Updates are available. Please see the references or vendor advisory for more information.
References
autojump 'custom_install' Directory Local Privilege Escalation Vulnerability
References:
References:
- autojump Homepage (Joel Schaerer)
- Bug 950777 - autojump: autojump profile will load random stuff from a directory (Red Hat)