VBox3 For ISDN4Linux Local Privilege Escalation Vulnerability
BID:9381
Info
VBox3 For ISDN4Linux Local Privilege Escalation Vulnerability
| Bugtraq ID: | 9381 |
| Class: | Design Error |
| CVE: |
CVE-2004-0015 |
| Remote: | No |
| Local: | Yes |
| Published: | Jan 07 2004 12:00AM |
| Updated: | Jul 12 2009 12:56AM |
| Credit: | This vulnerability was announced in a vendor security advisory. |
| Vulnerable: |
Michael Herold vbox3 3.0.1 .3 Michael Herold vbox3 3.0 _0.1.9 Michael Herold vbox3 3.0 _0.1.7 |
| Not Vulnerable: | |
Discussion
VBox3 For ISDN4Linux Local Privilege Escalation Vulnerability
vbox3 has been reported prone to a local privilege escalation vulnerability. The issue is reported to occur because the vbox3 software does not lower execution privilege before accepting and interpreting user-supplied scripts. A local user may potentially exploit this condition to have arbitrary code executed with elevated privileges.
vbox3 has been reported prone to a local privilege escalation vulnerability. The issue is reported to occur because the vbox3 software does not lower execution privilege before accepting and interpreting user-supplied scripts. A local user may potentially exploit this condition to have arbitrary code executed with elevated privileges.
Exploit / POC
VBox3 For ISDN4Linux Local Privilege Escalation Vulnerability
Currently we are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Currently we are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution / Fix
VBox3 For ISDN4Linux Local Privilege Escalation Vulnerability
Solution:
Debian has released an advisory (DSA 418-1) and fixes to address this issue. Users who are potentially affected by this issue are advised to apply appropriate fixes as soon as possible. Further information relating to obtaining and applying fixes can be found in the referenced advisory.
Michael Herold vbox3 3.0 _0.1.7
Solution:
Debian has released an advisory (DSA 418-1) and fixes to address this issue. Users who are potentially affected by this issue are advised to apply appropriate fixes as soon as possible. Further information relating to obtaining and applying fixes can be found in the referenced advisory.
Michael Herold vbox3 3.0 _0.1.7
-
Debian vbox3_0.1.7.1_alpha.deb
Debian GNU/Linux 3.0 (woody)
http://security.debian.org/pool/updates/main/v/vbox3/vbox3_0.1.7.1_alp ha.deb -
Debian vbox3_0.1.7.1_arm.deb
Debian GNU/Linux 3.0 (woody)
http://security.debian.org/pool/updates/main/v/vbox3/vbox3_0.1.7.1_arm .deb -
Debian vbox3_0.1.7.1_hppa.deb
Debian GNU/Linux 3.0 (woody)
http://security.debian.org/pool/updates/main/v/vbox3/vbox3_0.1.7.1_hpp a.deb -
Debian vbox3_0.1.7.1_i386.deb
Debian GNU/Linux 3.0 (woody)
http://security.debian.org/pool/updates/main/v/vbox3/vbox3_0.1.7.1_i38 6.deb -
Debian vbox3_0.1.7.1_ia64.deb
Debian GNU/Linux 3.0 (woody)
http://security.debian.org/pool/updates/main/v/vbox3/vbox3_0.1.7.1_ia6 4.deb -
Debian vbox3_0.1.7.1_m68k.deb
Debian GNU/Linux 3.0 (woody)
http://security.debian.org/pool/updates/main/v/vbox3/vbox3_0.1.7.1_m68 k.deb -
Debian vbox3_0.1.7.1_mips.deb
Debian GNU/Linux 3.0 (woody)
http://security.debian.org/pool/updates/main/v/vbox3/vbox3_0.1.7.1_mip s.deb -
Debian vbox3_0.1.7.1_mipsel.deb
Debian GNU/Linux 3.0 (woody)
http://security.debian.org/pool/updates/main/v/vbox3/vbox3_0.1.7.1_mip sel.deb -
Debian vbox3_0.1.7.1_powerpc.deb
Debian GNU/Linux 3.0 (woody)
http://security.debian.org/pool/updates/main/v/vbox3/vbox3_0.1.7.1_pow erpc.deb -
Debian vbox3_0.1.7.1_s390.deb
Debian GNU/Linux 3.0 (woody)
http://security.debian.org/pool/updates/main/v/vbox3/vbox3_0.1.7.1_s39 0.deb -
Debian vbox3_0.1.7.1_sparc.deb
Debian GNU/Linux 3.0 (woody)
http://security.debian.org/pool/updates/main/v/vbox3/vbox3_0.1.7.1_spa rc.deb
References
VBox3 For ISDN4Linux Local Privilege Escalation Vulnerability
References:
References: