XSOK GunZip Path Environment Variable Local Command Execution Vulnerability
BID:9321
Info
XSOK GunZip Path Environment Variable Local Command Execution Vulnerability
| Bugtraq ID: | 9321 |
| Class: | Input Validation Error |
| CVE: |
CVE-2003-0949 |
| Remote: | No |
| Local: | Yes |
| Published: | Dec 30 2003 12:00AM |
| Updated: | Jul 12 2009 12:56AM |
| Credit: | Discovery credited to Steve Kemp. |
| Vulnerable: |
xsok xsok 1.0 2 |
| Not Vulnerable: | |
Discussion
XSOK GunZip Path Environment Variable Local Command Execution Vulnerability
A problem has been disclosed in the handling of user-supplied input in xsok. Because of this, an attacker may be able to gain elevated privileges on a host with the vulnerable program. The program is typically installed with setgid games privileges.
A problem has been disclosed in the handling of user-supplied input in xsok. Because of this, an attacker may be able to gain elevated privileges on a host with the vulnerable program. The program is typically installed with setgid games privileges.
Exploit / POC
XSOK GunZip Path Environment Variable Local Command Execution Vulnerability
No exploit is required for this vulnerability.
No exploit is required for this vulnerability.
Solution / Fix
XSOK GunZip Path Environment Variable Local Command Execution Vulnerability
Solution:
Debian has made fixes available to resolve this issue. See Debian advisory DSA 405-1 for additional details.
xsok xsok 1.0 2
Solution:
Debian has made fixes available to resolve this issue. See Debian advisory DSA 405-1 for additional details.
xsok xsok 1.0 2
-
Debian xsok_1.02-9woody2_alpha.deb
Debian GNU/Linux 3.0 (woody)
http://security.debian.org/pool/updates/main/x/xsok/xsok_1.02-9woody2_ alpha.deb -
Debian xsok_1.02-9woody2_arm.deb
Debian GNU/Linux 3.0 (woody)
http://security.debian.org/pool/updates/main/x/xsok/xsok_1.02-9woody2_ arm.deb -
Debian xsok_1.02-9woody2_hppa.deb
Debian GNU/Linux 3.0 (woody)
http://security.debian.org/pool/updates/main/x/xsok/xsok_1.02-9woody2_ hppa.deb -
Debian xsok_1.02-9woody2_i386.deb
Debian GNU/Linux 3.0 (woody)
http://security.debian.org/pool/updates/main/x/xsok/xsok_1.02-9woody2_ i386.deb -
Debian xsok_1.02-9woody2_ia64.deb
Debian GNU/Linux 3.0 (woody)
http://security.debian.org/pool/updates/main/x/xsok/xsok_1.02-9woody2_ ia64.deb -
Debian xsok_1.02-9woody2_m68k.deb
Debian GNU/Linux 3.0 (woody)
http://security.debian.org/pool/updates/main/x/xsok/xsok_1.02-9woody2_ m68k.deb -
Debian xsok_1.02-9woody2_mips.deb
Debian GNU/Linux 3.0 (woody)
http://security.debian.org/pool/updates/main/x/xsok/xsok_1.02-9woody2_ mips.deb -
Debian xsok_1.02-9woody2_mipsel.deb
Debian GNU/Linux 3.0 (woody)
http://security.debian.org/pool/updates/main/x/xsok/xsok_1.02-9woody2_ mipsel.deb -
Debian xsok_1.02-9woody2_powerpc.deb
Debian GNU/Linux 3.0 (woody)
http://security.debian.org/pool/updates/main/x/xsok/xsok_1.02-9woody2_ powerpc.deb -
Debian xsok_1.02-9woody2_s390.deb
Debian GNU/Linux 3.0 (woody)
http://security.debian.org/pool/updates/main/x/xsok/xsok_1.02-9woody2_ s390.deb -
Debian xsok_1.02-9woody2_sparc.deb
Debian GNU/Linux 3.0 (woody)
http://security.debian.org/pool/updates/main/x/xsok/xsok_1.02-9woody2_ sparc.deb
References
XSOK GunZip Path Environment Variable Local Command Execution Vulnerability
References:
References: