|
|
|
Mup Local Arbitrary File Disclosure |
Si vous voulez bloquer ce service sur vos fils RSS
Si vous voulez nous contacter ou nous proposer un fil RSS
Menu > Articles de la revue de presse : - l'ensemble [ tous | francophone] - par mots clé [ tous] - par site [ tous] - le tagwall [ voir] - Top bi-hebdo de la revue de presse [ Voir]
Présentation : Mup is a shareware program for printing music. pourcents grep -B1 4755 mup-5.6 makefile For Linux console mode support, uncomment the following line chown root BINDIR mupdisp chmod 4755 BINDIR mupdisp pourcents ls -al usr bin mupdisp -rwsr-xr-x 1 root root 815245 2009-05-26 15 57 usr bin mupdisp pourcents usr bin mupdisp etc shadow Mupdisp - Version 5.6 Mup - Music Publisher Version 5.6 Copyright c 1995-2009 by Arkkra Enterprises. All rights reserved. etc shadow line 1 root 1 k.XXXXXXXXXXXXXXXXXXXXXXXXXX 14360 0 99999 7 ..... stopping due to previous errors pourcents Reading the first line of the grep output tells us that mupdist... -- mupdisp runs Mup and then runs GhostScript on the result. will be SUID root if the user enables Linux console mode support . Vendor Response The tgz version already does not use setuid, so there should be no issue for people installing from that, unless they explicitly choose to change the mode. The same is true for anyone compiling for themselves. We will change the rpm spec file to not do setuid. We can also suggest using sudo rather than setuid, which is a better alternative that was not available yet at the time mupdisp was originally written. This came after explaining that a workaround fix. Oh dear.
Les mots clés de la revue de presse pour cet article : local Les videos sur SecuObs pour les mots clés : local Les éléments de la revue Twitter pour les mots clé : local
Les derniers articles du site "Jeremy's Computer Security Blog" :
- What did they fix - Adobe Flash Temporary Filename Scheme - Reverse Engineering File Formats - Browser Fuzzer 3 - Writing Code that Breaks Code - Mozilla Code sighs - From Static Analysis to 0day Exploit - Some vendors are 'unconcerned' - Firefox Local Download Manager Vulnerability - Desktop Management Interface DMI
Menu > Articles de la revue de presse : - l'ensemble [ tous | francophone] - par mots clé [ tous] - par site [ tous] - le tagwall [ voir] - Top bi-hebdo de la revue de presse [ Voir]
Si vous voulez bloquer ce service sur vos fils RSS :
- avec iptables "iptables -A INPUT -s 88.191.75.173 --dport 80 -j DROP"
- avec ipfw et wipfw "ipfw add deny from 88.191.75.173 to any 80"
- Nous contacter par mail
| Mini-Tagwall des articles publiés sur SecuObs : | | | | sécurité, exploit, windows, attaque, outil, microsoft, réseau, audit, metasploit, vulnérabilité, système, virus, internet, usbsploit, données, source, linux, protocol, présentation, scanne, réseaux, scanner, bluetooth, conférence, reverse, shell, meterpreter, vista, rootkit, détection, mobile, security, malicieux, engineering, téléphone, paquet, trames, https, noyau, utilisant, intel, wishmaster, google, sysun, libre |
| Mini-Tagwall de l'annuaire video : | | | | curit, security, biomet, metasploit, biometric, cking, password, windows, botnet, defcon, tutorial, crypt, xploit, exploit, lockpicking, linux, attack, wireshark, vmware, rootkit, conference, network, shmoocon, backtrack, virus, conficker, elcom, etter, elcomsoft, server, meterpreter, openvpn, ettercap, openbs, iphone, shell, openbsd, iptables, securitytube, deepsec, source, office, systm, openssh, radio |
| Mini-Tagwall des articles de la revue de presse : | | | | security, microsoft, windows, hacker, attack, network, vulnerability, google, exploit, malware, internet, remote, iphone, server, inject, patch, apple, twitter, mobile, virus, ebook, facebook, vulnérabilité, crypt, source, linux, password, intel, research, virtual, phish, access, tutorial, trojan, social, privacy, firefox, adobe, overflow, office, cisco, conficker, botnet, pirate, sécurité |
| Mini-Tagwall des Tweets de la revue Twitter : | | | | security, linux, botnet, attack, metasploit, cisco, defcon, phish, exploit, google, inject, server, firewall, network, twitter, vmware, windows, microsoft, compliance, vulnerability, python, engineering, source, kernel, crypt, social, overflow, nessus, crack, hacker, virus, iphone, patch, virtual, javascript, malware, conficker, pentest, research, email, password, adobe, apache, proxy, backtrack |
|
|
|
|
|