Secunia Logo  


Secunia PSI WorldMap
 
File utility possible privilege escalation
Secunia Advisory: SA8224
Release Date: 2003-03-05
Popularity: 8,313 views

Critical:
Less critical
Impact: Privilege escalation
Where: Local system
Solution Status: Vendor Patch

OS:Conectiva Linux 6.0
Conectiva Linux 7.0
Conectiva Linux 8
Debian GNU/Linux 2.x
Debian GNU/Linux 3.0
EnGarde Secure Community 1.x
Gentoo Linux
Mandrake Linux 7.x
Mandrake Linux 8.x
Mandrake Linux 9.x
Red Hat Linux 6.2
Red Hat Linux 7.0
Red Hat Linux 7.1
Red Hat Linux 7.2
Red Hat Linux 7.3
Red Hat Linux 8.0
Sun Linux 5.x
SuSE Linux 7.x
SuSE Linux 8.x
Trustix Linux 1.0
Trustix Linux 1.1
Trustix Linux 1.2
Trustix Linux 1.5

Software:file 3.x

Secunia CVSS-2 Score: Available in Secunia business solutions

Subscribe: Instant alerts on relevant vulnerabilities


Advisory Content (Page 1 of 3)[ 1 ] [ 2 ] [ 3 ]

Description:
A boundary error identified in the utility "file" included in many *nix distributions can potentially be exploited by malicious users to escalate their privileges.

By crafting a speciel malicious file a user can cause a buffer overflow and potentially escalate his privileges to any user tricked into viewing the malicious file using the "file" utility.

It has also been reported that a malicious user can escalate privileges without other user interaction. This can be achieved by executing a program, which uses the "file" utility when determinig file types. This would gain the user the same privileges as the program calling "file".

Change Page:
[ 1 ] [ 2 ] [ 3 ]



Track this Secunia Advisory
Customers of the Secunia Vulnerability Intelligence solutions will automatically receive updates when new information regarding this advisory is released.

Read more about our Vulnerability Intelligence solutions and what they can do for you and your company.

About this Secunia Advisory
Please note: The information that this Secunia Advisory is based on comes from a third party unless stated otherwise.

Secunia collects, validates, and verifies all vulnerability reports issued by security research groups, vendors, and others.
  
Latest Advisories

Today
New advisories: 9
New vulnerabilities: 85
Updated advisories: 23

Less // 47 views
Debian update for cups
Moderately // 118 views
Red Hat update for tomcat
Highly // 160 views
HP-UX update for JRE / JDK
Highly // 131 views
Red Hat update for libvorbis

9th Nov, 2009
New advisories: 6
New vulnerabilities: 23
Updated advisories: 64


Solutions | More...  


Send Feedback to Secunia
If you have new information regarding this Secunia advisory or a product in our database, please send it to us using either our web form or email us at vuln@secunia.com.

Ideas, suggestions, and other feedback are most welcome.

Most Popular - 3 Hours

1. Oracle Document Capture EasyMail ActiveX Control Vulnerabilities // 95 views
2. Apple Mac OS X Security Update Fixes Multiple Vulnerabilities // 94 views
3. Sun Java JDK / JRE Multiple Vulnerabilities // 80 views
4. Internet Explorer Charset Inheritance Cross-Site Scripting Vulnerability // 48 views
5. Mozilla Firefox Multiple Vulnerabilities // 47 views
6. Spam Inspector EasyMail SMTP Object ActiveX Control Vulnerability // 44 views
7. Debian update for cups // 43 views
8. Adobe Flash Player Multiple Vulnerabilities // 40 views
9. CUPS "kerberos" Cross-Site Scripting Vulnerability // 35 views
10. Joomla! Article Manipulation and Version Information Disclosure // 34 views