First published: Wed May 21 2008(Updated: )
It was discovered that libraries shipped in sblim packages in Red Hat Enterprise Linux 4 and 5 have RPATH set pointing to a directory in a world-writable temporary directory: /var/tmp/sblim-<version>-<release>-root-brewbuilder//usr/lib . That directory existed on the build system during the package build, but is unlikely to exist on systems where sblim packages are installed. This issue can be exploited by a local user to create fake library required by sblim libraries and execute arbitrary code with the privileges of the application using sblim such as tog-pegasus.
Credit: secalert@redhat.com
Affected Software | Affected Version | How to fix |
---|---|---|
Redhat Enterprise Linux | =4 | |
Redhat Enterprise Linux | =5 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.