First Last Prev Next    No search results available      Search page      Enter new bug
Bug#: 68436
Alias:
Product:
Component:
Status: RESOLVED
Resolution: FIXED
Assigned To: Gentoo Security <security@gentoo.org>
Hardware:
OS:
Version:
Priority:
Severity:
Reporter: Luke Macken (RETIRED) <lewk@gentoo.org>
Add CC:
CC:
Remove selected CCs
URL:
Summary:
Status Whiteboard:
Keywords:
Flags: Requestee:
 
 
  ()

Filename Description Type Creator Created Size Actions
Create a New Attachment (proposed patch, testcase, etc.) View All

Bug 68436 depends on: Show dependency tree
Bug 68436 blocks:
Votes: 0    Show votes for this bug    Vote for this bug

Additional Comments: (this is where you put emerge --info)


Not eligible to see or edit group visibility for this bug.






View Bug Activity   |   Format For Printing   |   XML   |   Clone This Bug


Description:   Opened: 2004-10-21 12:36 0000
TITLE:
Speedtouch USB Driver Privilege Escalation Vulnerability

SECUNIA ADVISORY ID:
SA12916

VERIFY ADVISORY:
http://secunia.com/advisories/12916/

CRITICAL:
Less critical

IMPACT:
Privilege escalation

WHERE:
Local system

SOFTWARE:
Speedtouch USB driver 1.x
http://secunia.com/product/4124/

DESCRIPTION:
A vulnerability has been reported in Speedtouch USB Driver, which
potentially can be exploited by malicious, local users to gain
escalated privileges.

The vulnerability is caused due to an unspecified format string
errors in "modem_run", "pppoa2", and "pppoa3".

Successful exploitation may potentially allow execution of arbitrary
code with escalated privileges.

SOLUTION:
Update to version 1.3.1.
http://sourceforge.net/project/showfiles.php?group_id=32758&package_id=28264&release_id=271734

PROVIDED AND/OR DISCOVERED BY:
The vendor credits Max Vozeler.

ORIGINAL ADVISORY:
http://speedtouch.sourceforge.net/index.php?/news.en.html

- - -

See also: http://cve.mitre.org/cgi-bin/cvename.cgi?name=CAN-2004-0834

------- Comment #1 From Luke Macken (RETIRED) 2004-10-21 12:38:17 0000 -------
net-dialup,

please bump speedtouch to 1.3.1, thanks.

------- Comment #2 From Luke Macken (RETIRED) 2004-10-27 08:53:39 0000 -------
We should have had this GLSA out yesterday at the latest.

net-dialup, please bump package.

------- Comment #3 From Heinrich Wendel (RETIRED) 2004-10-27 09:31:15 0000 -------
commited 1.3.1 as x86

------- Comment #4 From Thierry Carrez (RETIRED) 2004-10-27 12:26:19 0000 -------
amd64, hppa, alpha : please test and mark net-dialup/speedtouch-1.3.1 stable

------- Comment #5 From Bryan Østergaard (RETIRED) 2004-10-28 02:42:30 0000 -------
Alpha stable.

------- Comment #6 From SpanKY 2004-10-31 01:24:35 0000 -------
hppa stable

------- Comment #7 From Simon Stelling (RETIRED) 2004-11-02 02:45:05 0000 -------
stable now on amd64
i couldn't really test it as i don't have a adsl-modem, but it seems to work. sorry for the big delay

------- Comment #8 From Luke Macken (RETIRED) 2004-11-02 06:22:06 0000 -------
GLSA 200411-04

First Last Prev Next    No search results available      Search page      Enter new bug