SGI Tempo '/opt/sgi/sgimc/bin/vx' Insecure File Permissions Vulnerability
BID:71667
Info
SGI Tempo '/opt/sgi/sgimc/bin/vx' Insecure File Permissions Vulnerability
| Bugtraq ID: | 71667 |
| Class: | Unknown |
| CVE: |
CVE-2014-7302 |
| Remote: | No |
| Local: | Yes |
| Published: | Dec 10 2014 12:00AM |
| Updated: | Dec 10 2014 12:00AM |
| Credit: | Luke Jennings, John Fitzpatrick MWR Labs |
| Vulnerable: |
SGI Tempo System 0 |
| Not Vulnerable: | |
Discussion
SGI Tempo '/opt/sgi/sgimc/bin/vx' Insecure File Permissions Vulnerability
SGI Tempo is prone to an insecure file-permissions vulnerability.
An attacker can exploit this issue to gain unauthorized access to create arbitrary files with root privileges.
SGI Tempo is prone to an insecure file-permissions vulnerability.
An attacker can exploit this issue to gain unauthorized access to create arbitrary files with root privileges.
Exploit / POC
SGI Tempo '/opt/sgi/sgimc/bin/vx' Insecure File Permissions Vulnerability
The researcher who discovered this issue has created a proof-of-concept. Please see the references for more information.
The researcher who discovered this issue has created a proof-of-concept. Please see the references for more information.
Solution / Fix
SGI Tempo '/opt/sgi/sgimc/bin/vx' Insecure File Permissions Vulnerability
Solution:
Currently, we are not aware of any vendor-supplied patches. If you feel we are in error or are aware of more recent information, please mail us at: [email protected].
Solution:
Currently, we are not aware of any vendor-supplied patches. If you feel we are in error or are aware of more recent information, please mail us at: [email protected].
References
SGI Tempo '/opt/sgi/sgimc/bin/vx' Insecure File Permissions Vulnerability
References:
References:
- SGI SUID Root Privilege Escalation (MWR Labs)
- Welcome to SGI (Silicon Graphics Inc.)