vendor:
Gallery
by:
Jon Hart
7.2
CVSS
HIGH
Insecure Shared Library Loading
427
CWE
Product Name: Gallery
Affected Version From: N/A
Affected Version To: N/A
Patch Exists: NO
Related CWE: N/A
CPE: N/A
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: Linux, *BSD, Solaris
2003
Apache::Gallery Insecure Shared Library Loading Vulnerability
Apache::Gallery, when using Inline C, stores shared libraries in an insecure fashion. As a result, an attacker may be capable of having malicious code linked into the Apache process. This could lead to a malicious local user gaining the privileges of the user invoking the Apache process, typically user nobody. It should be noted that for a successful exploitation, the libraries must be replaced prior to the Apache process being invoked.
Mitigation:
Ensure that the Apache::Gallery application is not installed in a world-writable directory, and that the shared libraries are not stored in a predictable location.