suidperl contains a flaw that may allow a local malicious user to gain access to unauthorized privileges. The issue is triggered when a user mounts media with files with a UID other than their own. The user can then run arbitrary scripts as that user (possibly root). Depending on the chosen script, this flaw may lead to a loss of confidentiality, integrity and/or availability.
Classification
Location:
Local Access Required
Attack Type:
Misconfiguration,
Race Condition
Impact:
Loss of Confidentiality,
Loss of Integrity,
Loss of Availability
Exploit:
Exploit Public
Disclosure:
OSVDB Verified
Solution
Upgrade to version 5.004_03 or higher, as it has been reported to fix this vulnerability. It is also possible to correct the flaw by implementing the following workaround(s): Do not let untrusted users mount media. A Patch for the vulnerable versions (4.x and 5.x) was also released.
This product uses the Daylife API but is not endorsed or certified by Daylife.
This section lists the latest news and blogs found via the daylife API (and for older items, the technorati API), which mention or otherwise discuss this vulnerability.