vendor:
a2ps
by:
lizard
7.5
CVSS
HIGH
Local Privilege Escalation
264
CWE
Product Name: a2ps
Affected Version From: Not available
Affected Version To: Not available
Patch Exists: NO
Related CWE: Not available
CPE: a:a2ps
Platforms Tested: Not available
2005
Local Privilege Escalation Exploit for a2ps
This is a local privilege escalation exploit for the a2ps program. It takes advantage of a vulnerability in the program to execute arbitrary code with root privileges. The exploit uses a shellcode to spawn a shell as root.
Mitigation:
The vendor should release a patch to fix the vulnerability. In the meantime, users can mitigate the risk by ensuring that the a2ps program is not setuid-root and by restricting access to the vulnerable binary.