vendor:
BRU
by:
Dvdman@l33tsecurity.com
7.2
CVSS
HIGH
Buffer Overflow
119
CWE
Product Name: BRU
Affected Version From: N/A
Affected Version To: N/A
Patch Exists: NO
Related CWE: N/A
CPE: N/A
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: Linux & FreeBsd
2003
EST BRU(TM) Backup and Restore Utility Local Root Exploit
It has been reported that BRU may not properly parse commandline arguments, potentially leading to at least two vectors of exploitation. It may be possible for local attackers to conduct format string-based attacks as well as buffer overflow-based attacks. It should be noted that although BRU does not ship with the suid bit set by default, documentation within the software may instruct users to enable it.
Mitigation:
Do not enable the suid bit for BRU.