PT-2008-1031 · Debian · Hf+1
Steve Kemp
·
Published
2008-11-26
·
Updated
2017-08-08
·
CVE-2008-2378
CVSS v2.0
7.2
High
| Vector | AV:L/AC:L/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
hf versions 0.7.3 through 0.8
Description
The issue concerns multiple vulnerabilities in the hf package of the Debian GNU/Linux operating system, which can be exploited by a local attacker to compromise the confidentiality, integrity, and availability of protected information. A specific vulnerability exists in the hfkernel, where improper handling of the -k option allows local users to gain privileges via a Trojan horse killall program in a directory in the PATH.
Recommendations
For versions 0.7.3 through 0.8, consider restricting access to the killall program to minimize the risk of exploitation until a patch is available.
As a temporary workaround, avoid using the -k option in the hfkernel until the issue is resolved.
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Debian
Hf