PT-2003-1806 · Kismac · Kismac

Publicado

2003-09-12

·

Atualizado

2017-07-11

·

CVE-2003-0703

CVSS v2.0

7.2

Alta

VetorAV:L/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions: KisMAC versions prior to 0.05d
Description: The issue allows local users to gain privileges by exploiting the trust in user-supplied variables to load arbitrary kernels or kernel modules. This can be achieved via the $DRIVER KEXT environment variable in scripts such as viha driver.sh, macjack load.sh, or airojack load.sh, or through similar techniques using exchangeKernel.sh.
Recommendations: For KisMAC versions prior to 0.05d, update to version 0.05d or later to resolve the issue. As a temporary workaround, consider restricting the use of the $DRIVER KEXT environment variable and limiting the execution of scripts like viha driver.sh, macjack load.sh, airojack load.sh, and exchangeKernel.sh to minimize the risk of exploitation.

Correção

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Identificadores relacionados

CVE-2003-0703

Produtos afetados

Kismac