Title: Adobe ColdFusion MX on Unix Permission Weakness Local Privilege Escalation
Info
Disclosure
Apr 10, 2007
Discovery
Unknown
Dates
Exploit
Unknown
Solution
Apr 10, 2007
Description
Classification
Location:
Local Access Required
Impact:
Loss of Integrity
Solution:
Workaround,
Patch / RCS
Exploit:
Exploit Private
Disclosure:
Vendor Verified
Solution
Adobe has released a patch to address this vulnerability. Additionally, it is possible to temporarily work around the flaw by implementing the following workaround: Change the permissions on the vulnerable scripts to be mode 0755.
Change the directory permissions of any 0777 permissions directories located under {cf_root}/verity/k2 to be 0755.