Linux cwdtools Vulnerabilities
BID:738
Info
Linux cwdtools Vulnerabilities
| Bugtraq ID: | 738 |
| Class: | Unknown |
| CVE: | |
| Remote: | No |
| Local: | Yes |
| Published: | Oct 22 1999 12:00AM |
| Updated: | Oct 22 1999 12:00AM |
| Credit: | This bug was apparently discovered by Brock Tellier and published in a S.u.S.E advisory on Oct 20, 1999. |
| Vulnerable: |
SuSE Linux 6.2 SuSE Linux 6.1 |
| Not Vulnerable: | |
Discussion
Linux cwdtools Vulnerabilities
cdwtools is a package of utilities for cd-writing. The linux version of these utilities, which ships with S.u.S.E linux 6.1 and 6.2, is vulnerable to several local root compromises. It is known that there are a number of ways to exploit these packages, including buffer overflows and /tmp symlink attacks.
cdwtools is a package of utilities for cd-writing. The linux version of these utilities, which ships with S.u.S.E linux 6.1 and 6.2, is vulnerable to several local root compromises. It is known that there are a number of ways to exploit these packages, including buffer overflows and /tmp symlink attacks.
Exploit / POC
Solution / Fix
Linux cwdtools Vulnerabilities
Solution:
S.u.S.E offers patched packages at the location below:
ftp://ftp.suse.com/pub/suse/i386/update/6.1/ap1/cdwtools-0.93-101.i386.rpm
ftp://ftp.suse.com/pub/suse/i386/update/6.2/ap1/cdwtools-0.93-100.i386.rpm
ftp://ftp.suse.com/pub/suse/axp/update/6.1/ap1/cdwtools-0.93-101.alpha.rpm
Solution:
S.u.S.E offers patched packages at the location below:
ftp://ftp.suse.com/pub/suse/i386/update/6.1/ap1/cdwtools-0.93-101.i386.rpm
ftp://ftp.suse.com/pub/suse/i386/update/6.2/ap1/cdwtools-0.93-100.i386.rpm
ftp://ftp.suse.com/pub/suse/axp/update/6.1/ap1/cdwtools-0.93-101.alpha.rpm