Secunia Logo  


Secunia PSI WorldMap
 
File utility possible privilege escalation
Secunia Advisory: SA8224
Release Date: 2003-03-05
Popularity: 8,353 views

Critical:
Less critical
Impact: Privilege escalation
Where: Local system
Solution Status: Vendor Patch

OS:Conectiva Linux 6.0
Conectiva Linux 7.0
Conectiva Linux 8
Debian GNU/Linux 2.x
Debian GNU/Linux 3.0
EnGarde Secure Community 1.x
Gentoo Linux
Mandrake Linux 7.x
Mandrake Linux 8.x
Mandrake Linux 9.x
Red Hat Linux 6.2
Red Hat Linux 7.0
Red Hat Linux 7.1
Red Hat Linux 7.2
Red Hat Linux 7.3
Red Hat Linux 8.0
Sun Linux 5.x
SuSE Linux 7.x
SuSE Linux 8.x
Trustix Linux 1.0
Trustix Linux 1.1
Trustix Linux 1.2
Trustix Linux 1.5

Software:file 3.x

Secunia CVSS-2 Score: Available in Secunia business solutions

Subscribe: Instant alerts on relevant vulnerabilities


Advisory Content (Page 1 of 3)[ 1 ] [ 2 ] [ 3 ]

Description:
A boundary error identified in the utility "file" included in many *nix distributions can potentially be exploited by malicious users to escalate their privileges.

By crafting a speciel malicious file a user can cause a buffer overflow and potentially escalate his privileges to any user tricked into viewing the malicious file using the "file" utility.

It has also been reported that a malicious user can escalate privileges without other user interaction. This can be achieved by executing a program, which uses the "file" utility when determinig file types. This would gain the user the same privileges as the program calling "file".

Change Page:
[ 1 ] [ 2 ] [ 3 ]



Track this Secunia Advisory
Customers of the Secunia Vulnerability Intelligence solutions will automatically receive updates when new information regarding this advisory is released.

Read more about our Vulnerability Intelligence solutions and what they can do for you and your company.

About this Secunia Advisory
Please note: The information that this Secunia Advisory is based on comes from a third party unless stated otherwise.

Secunia collects, validates, and verifies all vulnerability reports issued by security research groups, vendors, and others.
  
Latest Advisories

Send Feedback to Secunia
If you have new information regarding this Secunia advisory or a product in our database, please send it to us using either our web form or email us at vuln@secunia.com.

Ideas, suggestions, and other feedback are most welcome.

Most Popular - 3 Hours

1. Adobe Flash Player Multiple Vulnerabilities // 46 views
2. Adobe Reader/Acrobat "Doc.media.newPlayer()" Memory Corruption // 34 views
3. Intel Trusted Execution Technology SINIT Security Bypass // 20 views
4. Mozilla Firefox Multiple Vulnerabilities // 20 views
5. Pre Hotels & Resorts Management System SQL Injection Vulnerabilities // 20 views
6. Condor Job Management Security Bypass Vulnerability // 19 views
7. Ultimate Uploader for PHP Arbitrary File Upload Vulnerability // 19 views
8. SQL-Ledger Multiple Vulnerabilities // 18 views
9. Trac Reports Alternate Formats Information Disclosure Vulnerability // 17 views
10. Social Web CMS Cross-Site Scripting and Request Forgery Vulnerabilities // 17 views