OSVDB ID: 34930

Title: Adobe ColdFusion MX on Unix Permission Weakness Local Privilege Escalation

Info

Disclosure

Apr 10, 2007

Discovery

Unknown

Dates

Exploit

Unknown

Solution

Apr 10, 2007

Description

Classification

Location: Local Access Required
Impact: Loss of Integrity
Solution: Workaround, Patch / RCS
Exploit: Exploit Private
Disclosure: Vendor Verified

Solution

Adobe has released a patch to address this vulnerability. Additionally, it is possible to temporarily work around the flaw by implementing the following workaround: Change the permissions on the vulnerable scripts to be mode 0755. Change the directory permissions of any 0777 permissions directories located under {cf_root}/verity/k2 to be 0755.

Products

Unknown or Incomplete

References

Credit

Unknown or Incomplete



Direct URL: http://osvdb.org/34930