vendor:
KTVision
by:
IhaQueR
7.2
CVSS
HIGH
Symbolic Link Attack
59
CWE
Product Name: KTVision
Affected Version From: 0.1.1-271
Affected Version To: 0.1.1-271
Patch Exists: NO
Related CWE: N/A
CPE: a:kde:ktvision
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: Unix K Desktop Environment
2002
KTVision <= 0.1.1-271 local r00t exploit by IhaQueR
KTVision works with frame-grabber cards and KDE (Unix K Desktop Environment) to support TV video display on the PC screen. KTVision is vulnerable to symbolic link attacks. It is possible for an attacker to anticipate the expected name of a KTVision config file. A local attacker can then create a symbolic link with the anticipated filename pointing to files on the system writable by ktvision, (which is frequently suid root). This could allow an attacker to overwrite any file on the filesystem, completely undermining the the security of the exploited system.
Mitigation:
Ensure that the KTVision config file is not writable by any user other than the root user.