PT-2018-5054 · Apache · Apache Couchdb
Hyp3Rlinx
+1
·
Publicado
2018-02-12
·
Atualizado
2018-03-14
·
CVE-2016-8742
CVSS v3.1
7.8
Alta
| Vetor | AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Apache CouchDB version 2.0.0
Description
The issue concerns a local privilege escalation vulnerability in the Windows installer provided by the Apache CouchDB team. This vulnerability allows a non-privileged user to substitute any executable for the
nssm.exe service launcher, or CouchDB batch or binary files, due to the file permissions inherited from the parent directory. Upon a subsequent service or server restart, the substituted binary will run with administrator privilege.Recommendations
For Apache CouchDB version 2.0.0, update to version 2.0.0.1 to resolve the issue.
Exploit
Correção
LPE
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Apache Couchdb