RealOne Player Insecure Configuration File Permission Local Privilege Escalation Vulnerability
BID:8571
Info
RealOne Player Insecure Configuration File Permission Local Privilege Escalation Vulnerability
| Bugtraq ID: | 8571 |
| Class: | Access Validation Error |
| CVE: | |
| Remote: | No |
| Local: | Yes |
| Published: | Sep 09 2003 12:00AM |
| Updated: | Sep 09 2003 12:00AM |
| Credit: | Discovery of this vulnerability has been credited to Jon Hart <[email protected]>. |
| Vulnerable: |
RealNetworks RealOne Player for Linux 2.2 Alpha |
| Not Vulnerable: | |
Discussion
RealOne Player Insecure Configuration File Permission Local Privilege Escalation Vulnerability
The configuration files for the RealOne Player are installed in the a hidden folder in a users home directory. The issue presents itself, because configuration files stored in this directory are installed with insecure permissions. This means that an attacker, who is in the same group as a target user, may modify RealOne Player configuration files and may thereby escalate privileges to that of the target user.
The configuration files for the RealOne Player are installed in the a hidden folder in a users home directory. The issue presents itself, because configuration files stored in this directory are installed with insecure permissions. This means that an attacker, who is in the same group as a target user, may modify RealOne Player configuration files and may thereby escalate privileges to that of the target user.
Exploit / POC
RealOne Player Insecure Configuration File Permission Local Privilege Escalation Vulnerability
The following proof of concept exploit has been supplied:
The following proof of concept exploit has been supplied:
Solution / Fix
RealOne Player Insecure Configuration File Permission Local Privilege Escalation Vulnerability
Solution:
It has been reported that a fix to address this issue is pending release.
Solution:
It has been reported that a fix to address this issue is pending release.
References
RealOne Player Insecure Configuration File Permission Local Privilege Escalation Vulnerability
References:
References:
- RealPlayer Homepage (Real Networks)