PT-2018-5054 · Apache · Apache Couchdb

Hyp3Rlinx

+1

·

Publicado

2018-02-12

·

Atualizado

2018-03-14

·

CVE-2016-8742

CVSS v3.1

7.8

Alta

VetorAV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Apache CouchDB version 2.0.0
Description The issue concerns a local privilege escalation vulnerability in the Windows installer provided by the Apache CouchDB team. This vulnerability allows a non-privileged user to substitute any executable for the nssm.exe service launcher, or CouchDB batch or binary files, due to the file permissions inherited from the parent directory. Upon a subsequent service or server restart, the substituted binary will run with administrator privilege.
Recommendations For Apache CouchDB version 2.0.0, update to version 2.0.0.1 to resolve the issue.

Exploit

Correção

LPE

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2016-8742

Produtos afetados

Apache Couchdb