Node Packaged Modules Symlink Attack Local Privilege Escalation Vulnerability
BID:61083
Info
Node Packaged Modules Symlink Attack Local Privilege Escalation Vulnerability
| Bugtraq ID: | 61083 |
| Class: | Unknown |
| CVE: |
CVE-2013-4116 |
| Remote: | No |
| Local: | Yes |
| Published: | Jul 08 2013 12:00AM |
| Updated: | Jul 23 2013 08:14PM |
| Credit: | Daniel Kahn Gillmor |
| Vulnerable: | |
| Not Vulnerable: | |
Discussion
Node Packaged Modules Symlink Attack Local Privilege Escalation Vulnerability
Node Packaged Modules is prone to a local privilege-escalation vulnerability.
An attacker with local access could potentially exploit this issue to perform symbolic-link attacks, overwriting arbitrary files in the context of the affected application.
Successfully mounting a symlink attack may allow the attacker to delete or corrupt sensitive files, which may result in escalation of privileges or a denial of service. Other attacks may also be possible.
Node Packaged Modules is prone to a local privilege-escalation vulnerability.
An attacker with local access could potentially exploit this issue to perform symbolic-link attacks, overwriting arbitrary files in the context of the affected application.
Successfully mounting a symlink attack may allow the attacker to delete or corrupt sensitive files, which may result in escalation of privileges or a denial of service. Other attacks may also be possible.
Exploit / POC
Node Packaged Modules Symlink Attack Local Privilege Escalation Vulnerability
An attacker can use readily available commands to exploit the issue.
An attacker can use readily available commands to exploit the issue.
Solution / Fix
Node Packaged Modules Symlink Attack Local Privilege Escalation Vulnerability
Solution:
Updates are available. Please see the references or vendor advisory for more information.
Solution:
Updates are available. Please see the references or vendor advisory for more information.
References
Node Packaged Modules Symlink Attack Local Privilege Escalation Vulnerability
References:
References: