vendor:
ja-elvis and ko-helvis
by:
dethy
7.5
CVSS
HIGH
Buffer Overflow
120
CWE
Product Name: ja-elvis and ko-helvis
Affected Version From: Versions prior to ja-elvis-1.8.4_1 and ko-helvis-1.8h2_1
Affected Version To: Not provided
Patch Exists: YES
Related CWE: Not provided
CPE: Not provided
Platforms Tested: FreeBSD 3.5.1 and 4.2
2001
FreeBSD ja-elvis & ko-helvis Local Root Exploit
The ja-elvis and ko-helvis packages on FreeBSD versions prior to ja-elvis-1.8.4_1 and ko-helvis-1.8h2_1 contain a file recovery utility called 'elvrec' that is installed suid root(4755) by default. This utility is vulnerable to a buffer overflow, which can be exploited to gain root privileges.
Mitigation:
Upgrade to ja-elvis-1.8.4_1 or ko-helvis-1.8h2_1 or later versions.