Início
Tendências
Vulnerabilidades
Notícias
Pesquisadores
Por que dbugs?

Xavier De Leon

Pesquisador detigerteam.se
#50454de 53,638
4.6CVSS total
Vulnerabilidades · 1
PT-2006-4559
4.6
2006-07-19
Rocks · Rocks Clusters · CVE-2006-3693
**Name of the Vulnerable Software and Affected Versions** Rocks Clusters versions 4.1 and earlier **Description** The issue allows local users to gain privileges via commands enclosed with escaped backticks (``) in an argument to the (1) mount-loop or (2) umount-loop command. This is possible because the input is not properly filtered in a system function call, specifically in the mount-loop.c and umount-loop.c files. **Recommendations** For versions 4.1 and earlier, consider restricting the use of the mount-loop and umount-loop commands until a proper fix is applied, and ensure that all system function calls properly filter input to prevent privilege escalation.