vendor:
SUSE Linux Enterprise Server
by:
Unknown
7.2
CVSS
HIGH
Privilege Escalation
264
CWE
Product Name: SUSE Linux Enterprise Server
Affected Version From: S.u.S.E. 6.4
Affected Version To: S.u.S.E. 6.4
Patch Exists: NO
Related CWE: CVE-2002-0395
CPE: o:suse:suse_linux_enterprise_server:6.4
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: Linux
2002
KSCD SGID Disk Shell Vulnerability
Some Linux distributions (S.u.S.E. 6.4 reported) ship with kscd (a CD player for the KDE Desktop) sgid disk. kscd uses the contents of the 'SHELL' environment variable to execute a browser. This makes it possible to obtain a sgid 'disk' shell. Using these privileges along with code provided in the exploit, it is possible to change attributes on raw disks. This in turns allows an attacker to create a root shell, thus compromising the intergrity of the machine.
Mitigation:
Red Hat, Linux Mandrake, and Turbo Linux do not currently ship with kscd setgid 'disk'.