ppc64-diag CVE-2014-4039 Multiple Insecure File Permissions Vulnerabilities
BID:68086
Info
ppc64-diag CVE-2014-4039 Multiple Insecure File Permissions Vulnerabilities
| Bugtraq ID: | 68086 |
| Class: | Design Error |
| CVE: |
CVE-2014-4039 |
| Remote: | No |
| Local: | Yes |
| Published: | Jun 13 2014 12:00AM |
| Updated: | Aug 12 2015 10:11PM |
| Credit: | Vincent Danen |
| Vulnerable: |
SuSE SUSE Linux Enterprise Server 11 SP3 S.u.S.E. openSUSE 12.3 Redhat Enterprise Linux Server 6 Eclipse ppc64-diag 2.6.1 |
| Not Vulnerable: | |
Discussion
ppc64-diag CVE-2014-4039 Multiple Insecure File Permissions Vulnerabilities
ppc64-diag is prone to multiple insecure file-permissions vulnerabilities.
A local attacker can exploit these issues to obtain potentially sensitive information, that may aid in further attacks.
ppc64-diag 2.6.1 is vulnerable; other versions may also be affected.
ppc64-diag is prone to multiple insecure file-permissions vulnerabilities.
A local attacker can exploit these issues to obtain potentially sensitive information, that may aid in further attacks.
ppc64-diag 2.6.1 is vulnerable; other versions may also be affected.
Exploit / POC
ppc64-diag CVE-2014-4039 Multiple Insecure File Permissions Vulnerabilities
Attackers can use readily available tools and standard commands to exploit these issues.
Attackers can use readily available tools and standard commands to exploit these issues.
Solution / Fix
ppc64-diag CVE-2014-4039 Multiple Insecure File Permissions Vulnerabilities
Solution:
Currently we are not aware of any vendor-supplied patches. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Solution:
Currently we are not aware of any vendor-supplied patches. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
References
ppc64-diag CVE-2014-4039 Multiple Insecure File Permissions Vulnerabilities
References:
References: