DavFS2 'system()' Function Local Privilege Escalation Vulnerability
BID:62445
Info
DavFS2 'system()' Function Local Privilege Escalation Vulnerability
| Bugtraq ID: | 62445 |
| Class: | Unknown |
| CVE: |
CVE-2013-4362 |
| Remote: | No |
| Local: | Yes |
| Published: | Sep 15 2013 12:00AM |
| Updated: | Dec 20 2016 06:05AM |
| Credit: | Werner Baumann |
| Vulnerable: |
Mandriva Business Server 1 X86 64 Mandriva Business Server 1 MandrakeSoft Enterprise Server 5 x86_64 MandrakeSoft Enterprise Server 5 Gentoo Linux Debian Linux 6.0 sparc Debian Linux 6.0 s/390 Debian Linux 6.0 powerpc Debian Linux 6.0 mips Debian Linux 6.0 ia-64 Debian Linux 6.0 ia-32 Debian Linux 6.0 arm Debian Linux 6.0 amd64 Davfs2 Davfs2 1.4.7 Davfs2 Davfs2 1.4.6 |
| Not Vulnerable: | |
Discussion
DavFS2 'system()' Function Local Privilege Escalation Vulnerability
DavFS2 is prone to a local privilege-escalation vulnerability.
Local attackers can exploit this issue to gain elevated privileges on affected computers. Other attacks are also possible.
DavFS2 1.4.6 and 1.4.7 are vulnerable.
DavFS2 is prone to a local privilege-escalation vulnerability.
Local attackers can exploit this issue to gain elevated privileges on affected computers. Other attacks are also possible.
DavFS2 1.4.6 and 1.4.7 are vulnerable.
Exploit / POC
DavFS2 'system()' Function Local Privilege Escalation Vulnerability
The following exploit is available:
The following exploit is available:
Solution / Fix
DavFS2 'system()' Function Local Privilege Escalation Vulnerability
Solution:
Updates are available. Please see the references or vendor advisory for more information.
MandrakeSoft Enterprise Server 5
Mandriva Business Server 1 X86 64
MandrakeSoft Enterprise Server 5 x86_64
Solution:
Updates are available. Please see the references or vendor advisory for more information.
MandrakeSoft Enterprise Server 5
-
Mandriva davfs2-1.3.3-1.1mdvmes5.2.i586.rpm
http://www.mandriva.com/en/downloads/
Mandriva Business Server 1 X86 64
-
Mandriva davfs2-1.4.6-2.1.mbs1.x86_64.rpm
http://www.mandriva.com/en/downloads/
MandrakeSoft Enterprise Server 5 x86_64
-
Mandriva davfs2-1.3.3-1.1mdvmes5.2.x86_64.rpm
http://www.mandriva.com/en/downloads/
References
DavFS2 'system()' Function Local Privilege Escalation Vulnerability
References:
References:
- Davfs2 Homepage (Davfs2)
- Debian Bug report logs - #723034 (Werner Baumann)
- Re: CVE request: davfs2 - Unsecure use of system() (SecLists.Org)