PT-2006-4559 · Rocks · Rocks Clusters

Xavier De Leon

·

Publicado

2006-07-19

·

Atualizado

2018-10-18

·

CVE-2006-3693

CVSS v2.0

4.6

Média

VetorAV:L/AC:L/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions Rocks Clusters versions 4.1 and earlier
Description The issue allows local users to gain privileges via commands enclosed with escaped backticks (``) in an argument to the (1) mount-loop or (2) umount-loop command. This is possible because the input is not properly filtered in a system function call, specifically in the mount-loop.c and umount-loop.c files.
Recommendations For versions 4.1 and earlier, consider restricting the use of the mount-loop and umount-loop commands until a proper fix is applied, and ensure that all system function calls properly filter input to prevent privilege escalation.

Exploit

Correção

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Identificadores relacionados

CVE-2006-3693

Produtos afetados

Rocks Clusters