vendor:
Patrol 3.2
by:
maheaa
7.2
CVSS
HIGH
Local Root Compromise or Denial of Service
264
CWE
Product Name: Patrol 3.2
Affected Version From: Patrol 3.2
Affected Version To: Patrol 3.2
Patch Exists: NO
Related CWE: N/A
CPE: N/A
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: HP-UX
1998
Patrol 3.2 Local Root Compromise or Denial of Service
Patrol 3.2, installed out of the box, allows for a local root compromise or denial of service. The vulnerability lies in the creation of a file by snmpagnt that is owned by the owner of the parent directory of the file and possibly world writeable. A local user can specify any file (/.rhosts) and create it / set the permissions according to the user's umask.
Mitigation:
Ensure that the snmpagnt file is not world writeable and that the umask is set to a secure value.